Звіт у форматі JSON машиночитний
{
"data": {
"repo": {
"topics": [],
"is_fork": false,
"size_kb": 797,
"has_wiki": true,
"homepage": null,
"languages": {
"JavaScript": 2030,
"TypeScript": 409203
},
"pushed_at": "2026-07-25T04:25:37Z",
"created_at": "2026-06-07T22:51:53Z",
"owner_type": "User",
"updated_at": "2026-07-25T04:25:58Z",
"description": "Generate and edit images with Google Gemini (Nano Banana / Nano Banana Pro) via the Gemini API",
"is_archived": false,
"is_disabled": false,
"license_spdx": "MIT",
"default_branch": "main",
"license_spdx_raw": "MIT",
"primary_language": "TypeScript",
"significant_languages": [
"TypeScript"
]
},
"owner": {
"blog": null,
"name": null,
"type": "User",
"login": "chrischall",
"company": null,
"location": null,
"followers": 10,
"avatar_url": "https://avatars.githubusercontent.com/u/10564245?v=4",
"created_at": "2015-01-16T16:58:09Z",
"is_verified": null,
"public_repos": 64,
"account_age_days": 4207
},
"license": {
"state": "standard",
"spdx_id": "MIT",
"raw_spdx": "MIT",
"file_present": true,
"scorecard_found": true,
"profile_has_license": true
},
"activity": {
"releases": [
{
"tag": "v1.0.3",
"kind": "patch",
"published_at": "2026-07-19T16:48:49Z"
},
{
"tag": "v1.0.2",
"kind": "patch",
"published_at": "2026-07-19T12:45:50Z"
},
{
"tag": "v1.0.1",
"kind": "patch",
"published_at": "2026-07-14T10:40:15Z"
},
{
"tag": "v1.0.0",
"kind": "major",
"published_at": "2026-07-08T15:13:45Z"
},
{
"tag": "v0.9.0",
"kind": "minor",
"published_at": "2026-07-08T13:48:39Z"
},
{
"tag": "v0.8.0",
"kind": "minor",
"published_at": "2026-07-07T15:08:18Z"
},
{
"tag": "v0.7.2",
"kind": "patch",
"published_at": "2026-07-06T14:13:59Z"
},
{
"tag": "v0.7.1",
"kind": "patch",
"published_at": "2026-07-06T12:32:34Z"
},
{
"tag": "v0.7.0",
"kind": "minor",
"published_at": "2026-07-06T07:08:04Z"
},
{
"tag": "v0.6.1",
"kind": "patch",
"published_at": "2026-07-05T23:00:09Z"
},
{
"tag": "v0.6.0",
"kind": "minor",
"published_at": "2026-06-13T00:53:45Z"
},
{
"tag": "v0.5.0",
"kind": "minor",
"published_at": "2026-06-10T02:09:21Z"
},
{
"tag": "v0.4.0",
"kind": "minor",
"published_at": "2026-06-08T14:42:33Z"
},
{
"tag": "v0.3.0",
"kind": "minor",
"published_at": "2026-06-08T13:09:51Z"
},
{
"tag": "v0.2.0",
"kind": "minor",
"published_at": "2026-06-08T01:11:17Z"
}
],
"recent_commits": [
{
"oid": "e574b2ce7cd47d7dfc0ac14132e44aaeae0e332f",
"body": "…(#101)\n\n`sharp` 0.34.5 carries a HIGH advisory for vulnerabilities inherited from\nlibvips, patched in 0.35.0. It is not a dependency of this server — it arrives\ntransitively as `@cloudflare/vitest-pool-workers` → `miniflare` → `sharp`, i.e.\npurely the Workers test harness. Updating the pool moves m\n[…]\n postcss 8.5.17 → 8.5.23 (source-map path traversal, patched 8.5.18),\nanother vite/vitest transitive that likewise never reaches the bundle.\n\nLockfile only; node and Workers-runtime suites both green.",
"is_bot": false,
"headline": "build(deps): bump the test toolchain past the sharp libvips advisory …",
"author_name": "chrischall",
"author_login": "chrischall",
"committed_at": "2026-07-25T04:25:35Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "044ae1b97c7524be163a6bdd23f8b831b339f151",
"body": "Bumps [fast-uri](https://github.com/fastify/fast-uri) from 3.1.2 to 3.1.4.\n- [Release notes](https://github.com/fastify/fast-uri/releases)\n- [Commits](https://github.com/fastify/fast-uri/compare/v3.1.2...v3.1.4)\n\n---\nupdated-dependencies:\n- dependency-name: fast-uri\n dependency-version: 3.1.4\n dependency-type: indirect\n...\n\nSigned-off-by: dependabot[bot] <support@github.com>\nCo-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>",
"is_bot": true,
"headline": "build(deps): Bump fast-uri from 3.1.2 to 3.1.4 (#100)",
"author_name": "dependabot[bot]",
"author_login": "dependabot[bot]",
"committed_at": "2026-07-24T00:00:09Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "842f048fd8fc17c6c21aa5f0819e0bd4784f5f31",
"body": "Bumps [hono](https://github.com/honojs/hono) from 4.12.26 to 4.12.31.\n- [Release notes](https://github.com/honojs/hono/releases)\n- [Commits](https://github.com/honojs/hono/compare/v4.12.26...v4.12.31)\n\n---\nupdated-dependencies:\n- dependency-name: hono\n dependency-version: 4.12.31\n dependency-type: indirect\n...\n\nSigned-off-by: dependabot[bot] <support@github.com>\nCo-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>",
"is_bot": true,
"headline": "build(deps): Bump hono from 4.12.26 to 4.12.31 (#99)",
"author_name": "dependabot[bot]",
"author_login": "dependabot[bot]",
"committed_at": "2026-07-24T00:00:01Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "cdba453851c7df96408f896523727907b066e42d",
"body": "Bumps [body-parser](https://github.com/expressjs/body-parser) from 2.2.2 to 2.3.0.\n- [Release notes](https://github.com/expressjs/body-parser/releases)\n- [Changelog](https://github.com/expressjs/body-parser/blob/master/HISTORY.md)\n- [Commits](https://github.com/expressjs/body-parser/compare/v2.2.2..\n[…]\nser\n dependency-version: 2.3.0\n dependency-type: indirect\n...\n\nSigned-off-by: dependabot[bot] <support@github.com>\nCo-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>",
"is_bot": true,
"headline": "build(deps): Bump body-parser from 2.2.2 to 2.3.0 (#98)",
"author_name": "dependabot[bot]",
"author_login": "dependabot[bot]",
"committed_at": "2026-07-23T23:58:01Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "150585cb74193d94d214fa876217ae60d8426eb1",
"body": "The deploy-connector job passed `secrets: inherit`, handing the reusable\nworkflow every repo secret — RELEASE_PAT, CLAWHUB_TOKEN and the rest — when\nall it needs is the Cloudflare API token and account ID. Pass those two\nexplicitly instead. The job also inherited release-please.yml's workflow-level\n\n[…]\n their tag, and the workflow_dispatch stub\ndeploys any ref on demand.\n\n\nClaude-Session: https://claude.ai/code/session_01BvYhHrXacyknC2L9knjjdb\n\nCo-authored-by: Claude Opus 4.8 <noreply@anthropic.com>",
"is_bot": false,
"headline": "ci: scope deploy secrets and correct the manual-deploy docs (#97)",
"author_name": "chrischall",
"author_login": "chrischall",
"committed_at": "2026-07-20T14:56:06Z",
"body_truncated": true,
"is_coding_agent": true
},
{
"oid": "d3186409366d21f06c0852de3ed8b42ead455731",
"body": "The hosted connector was deployed by hand, so it could drift behind main —\ngogcli-mcp's had drifted far enough to keep serving a tool schema its repo had\nalready replaced. Deploying on release closes that gap.\n\nUses the shared reusable workflow from chrischall/workflows#51 rather than a\nlocal copy, \n[…]\nhe added workflow_dispatch stub allows redeploying any ref on demand.\n\n\nClaude-Session: https://claude.ai/code/session_01BvYhHrXacyknC2L9knjjdb\n\nCo-authored-by: Claude Opus 4.8 <noreply@anthropic.com>",
"is_bot": false,
"headline": "ci: deploy the connector Worker on release (#96)",
"author_name": "chrischall",
"author_login": "chrischall",
"committed_at": "2026-07-20T14:08:52Z",
"body_truncated": true,
"is_coding_agent": true
},
{
"oid": "53fa807c5beac2e45d037d7668b9435c6c7147e0",
"body": "Bumps the production-dependencies group with 1 update: [@chrischall/mcp-utils](https://github.com/chrischall/mcp-utils).\n\n\nUpdates `@chrischall/mcp-utils` from 0.13.0 to 0.13.3\n- [Release notes](https://github.com/chrischall/mcp-utils/releases)\n- [Changelog](https://github.com/chrischall/mcp-utils/b\n[…]\nte:semver-patch\n dependency-group: production-dependencies\n...\n\nSigned-off-by: dependabot[bot] <support@github.com>\nCo-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>",
"is_bot": true,
"headline": "build(deps): Bump @chrischall/mcp-utils (#95)",
"author_name": "dependabot[bot]",
"author_login": "dependabot[bot]",
"committed_at": "2026-07-19T19:33:42Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "f49b77284d184453f098fe86e2c5a95f4479fecb",
"body": "Bumps the dev-dependencies group with 1 update: [@chrischall/mcp-connector](https://github.com/chrischall/mcp-connector).\n\n\nUpdates `@chrischall/mcp-connector` from 1.0.0 to 1.1.0\n- [Release notes](https://github.com/chrischall/mcp-connector/releases)\n- [Changelog](https://github.com/chrischall/mcp-\n[…]\non-update:semver-minor\n dependency-group: dev-dependencies\n...\n\nSigned-off-by: dependabot[bot] <support@github.com>\nCo-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>",
"is_bot": true,
"headline": "build(deps-dev): Bump @chrischall/mcp-connector (#94)",
"author_name": "dependabot[bot]",
"author_login": "dependabot[bot]",
"committed_at": "2026-07-19T19:33:35Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "2411f4fa3d1251ee64a1ffbf17da35f4af952713",
"body": null,
"is_bot": false,
"headline": "chore(main): release 1.0.3 (#84)",
"author_name": "chrischall",
"author_login": "chrischall",
"committed_at": "2026-07-19T16:48:38Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "28c059b55b1ad366e686caa9a197a40ce5b67607",
"body": "CI delegates to the shared reusable workflow with `test-command: npm test`,\nso only what that script reaches actually runs. `npm run worker:test` and\n`npm run worker:typecheck` were reachable from neither — meaning nothing in\nCI covered src/worker.ts or src/gemini-auth.ts, and the workers pool (the\n\n[…]\nnce a dropped gate fails\nsilently — coverage just stops.\n\n\nClaude-Session: https://claude.ai/code/session_01NeQhaVVGXZWoy7HQWssDdg\n\nCo-authored-by: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
"is_bot": false,
"headline": "ci: run the worker suite and worker typecheck in CI (#93)",
"author_name": "chrischall",
"author_login": "chrischall",
"committed_at": "2026-07-19T16:23:24Z",
"body_truncated": true,
"is_coding_agent": true
},
{
"oid": "041091dff6a907da0f45ea7f2d4af7b409312a9c",
"body": "* feat(connector): serve gemini-mcp as a Cloudflare Worker hosted connector\n\nAdds the claude.ai remote MCP connector on top of the transport-neutral\nregistrars and the wrangler scaffold.\n\n- src/gemini-auth.ts: ConnectorAuth with one API-key field, verified at\n login with a live listModels() call. T\n[…]\ne Opus 4.8 (1M context) <noreply@anthropic.com>\nClaude-Session: https://claude.ai/code/session_01NeQhaVVGXZWoy7HQWssDdg\n\n---------\n\nCo-authored-by: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
"is_bot": false,
"headline": "feat(connector): hosted Cloudflare Worker connector for claude.ai (#91)",
"author_name": "chrischall",
"author_login": "chrischall",
"committed_at": "2026-07-19T15:16:38Z",
"body_truncated": true,
"is_coding_agent": true
},
{
"oid": "34c24b375fbd3c94d8133b5148ebe53298c0f3a6",
"body": "* chore(connector): add Cloudflare Worker deploy scaffold\n\nConfig, dependencies and operator docs for the remote MCP connector\nWorker. No worker code — src/worker.ts lands separately.\n\n- wrangler.jsonc: gemini-connector, nodejs_compat, GeminiMcpAgent DO\n (sqlite migration v1), OAUTH_KV (binding nam\n[…]\ne Opus 4.8 (1M context) <noreply@anthropic.com>\nClaude-Session: https://claude.ai/code/session_01NeQhaVVGXZWoy7HQWssDdg\n\n---------\n\nCo-authored-by: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
"is_bot": false,
"headline": "chore(connector): add Cloudflare Worker deploy scaffold (#90)",
"author_name": "chrischall",
"author_login": "chrischall",
"committed_at": "2026-07-19T15:10:22Z",
"body_truncated": true,
"is_coding_agent": true
},
{
"oid": "3bf6411da38b460e845963a26bb7dd508a694387",
"body": "Every `register<X>Tools` now takes the client as its second argument and\nimports only the *type* from `../client.js`, so a non-stdio entry point can\nbuild one client PER AUTHENTICATED USER instead of sharing the env-driven\nprocess singleton. `resolveVideoInput` (tools/shared.ts) takes the client as \n[…]\nan injected stub client and never touches the singleton.\n\n\nClaude-Session: https://claude.ai/code/session_01NeQhaVVGXZWoy7HQWssDdg\n\nCo-authored-by: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
"is_bot": false,
"headline": "refactor(tools): inject the GeminiClient into the tool registrars (#89)",
"author_name": "chrischall",
"author_login": "chrischall",
"committed_at": "2026-07-19T15:04:55Z",
"body_truncated": true,
"is_coding_agent": true
},
{
"oid": "abb6b17b6323d7b54aee550a835ffdd96d6a3bb4",
"body": "Agent worktrees are created at `.claude/worktrees/<name>/` — each a full\ncheckout of this repo, tests included. Vitest's default excludes cover\nnode_modules and dist but not `.claude/`, so every worktree's copy of the\nsuite was collected alongside the real one.\n\nThe failure is silent and actively mi\n[…]\nlso gitignore `.claude/` (nothing under it was tracked).\n\n\nClaude-Session: https://claude.ai/code/session_01NeQhaVVGXZWoy7HQWssDdg\n\nCo-authored-by: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
"is_bot": false,
"headline": "fix(tests): exclude agent worktrees from vitest collection (#88)",
"author_name": "chrischall",
"author_login": "chrischall",
"committed_at": "2026-07-19T15:01:23Z",
"body_truncated": true,
"is_coding_agent": true
},
{
"oid": "ccfe5bc80a0a5adfccafa1e9cae5df1470c44f88",
"body": "* fix(client): wait out interactions-store lag for 120s, not 6s\n\nThe reported \"chain expired\" failures were not expired chains. The\ninteractions store is eventually consistent: docs/GEMINI-API.md records\n(live, 2026-07-06, verified against a real failing id created moments\nbefore the failure) that a\n[…]\ne Opus 4.8 (1M context) <noreply@anthropic.com>\nClaude-Session: https://claude.ai/code/session_01NeQhaVVGXZWoy7HQWssDdg\n\n---------\n\nCo-authored-by: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
"is_bot": false,
"headline": "fix(client): wait out interactions-store lag for 120s, not 6s (#86)",
"author_name": "chrischall",
"author_login": "chrischall",
"committed_at": "2026-07-19T13:47:43Z",
"body_truncated": true,
"is_coding_agent": true
},
{
"oid": "656e0c115b620339eb3a258aa1dce219ca4e679a",
"body": "…est (#85)\n\n`postInteraction` relabelled ANY 404 as \"previous interaction not found\"\nwhenever the request merely carried a `previous_interaction_id`, and put\nthe upstream body in `cause` — which the surfaced message overrides and\nMCP serialization drops. The caller never saw what Gemini actually sai\n[…]\niation moved into the error message for the same reason.\n\n\nClaude-Session: https://claude.ai/code/session_01NeQhaVVGXZWoy7HQWssDdg\n\nCo-authored-by: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
"is_bot": false,
"headline": "fix(interact): stop blaming the chain for every 404 on a chained requ…",
"author_name": "chrischall",
"author_login": "chrischall",
"committed_at": "2026-07-19T13:08:35Z",
"body_truncated": true,
"is_coding_agent": true
},
{
"oid": "77fde2d43ddddc2a146773dc350d45c04b00ee11",
"body": "…g (#83)\n\nA multi-turn chain broke in two ways, both surfacing to the caller as\n\"the chain expired\" plus a manual re-anchor on the last output file:\n\n1. `continue_last` resumed a module-level `lastInteractionId` that dies\n with the server process. An MCP restart mid-workflow read as an\n expired \n[…]\nn't\nwrite sidecars, so there is nothing to re-anchor on.\n\n\nClaude-Session: https://claude.ai/code/session_01NeQhaVVGXZWoy7HQWssDdg\n\nCo-authored-by: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
"is_bot": false,
"headline": "fix(interact): recover expired chains from sidecars instead of failin…",
"author_name": "chrischall",
"author_login": "chrischall",
"committed_at": "2026-07-19T13:02:50Z",
"body_truncated": true,
"is_coding_agent": true
},
{
"oid": "38644d96ad9c2544dcff2e459831ef6a2191050b",
"body": null,
"is_bot": false,
"headline": "chore(main): release 1.0.2 (#82)",
"author_name": "chrischall",
"author_login": "chrischall",
"committed_at": "2026-07-19T12:45:36Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "67cde084a68f7be4466457c2b93a08768362fdd1",
"body": "The PR/auto-review block was byte-identical across ~40 repos and had\ndrifted into contradictory instructions — including telling an agent to\nself-arm ready-to-merge on a warn/fail verdict, against the global rule.\n\nPolicy now lives once in ~/.claude/CLAUDE.md; shared technical conventions\nin chrisch\n[…]\nd. Repo-specific content in\nthe old block was preserved.\n\n\nClaude-Session: https://claude.ai/code/session_01Div7Yto4QhW7M8i8i5wG6r\n\nCo-authored-by: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
"is_bot": false,
"headline": "docs: replace duplicated fleet policy with a pointer (#81)",
"author_name": "chrischall",
"author_login": "chrischall",
"committed_at": "2026-07-19T01:41:18Z",
"body_truncated": true,
"is_coding_agent": true
},
{
"oid": "fd7a7b18b9a13ff8143d39681ab4830282c32c84",
"body": null,
"is_bot": false,
"headline": "chore(main): release 1.0.1 (#79)",
"author_name": "chrischall",
"author_login": "chrischall",
"committed_at": "2026-07-14T10:40:05Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "511d901f0e40a5e336c71df833b0e8354dd52070",
"body": "…ing (#80)\n\n* fix(plugin): move SKILL.md into skills/ directory so plugin skills load\n\nClaude Code requires plugin skills entries to be directories containing SKILL.md; the root-level file reference fails to load. Move the skill to skills/gemini-mcp/ and point plugin.json at ./skills/ per the fleet \n[…]\nlaude Fable 5 <noreply@anthropic.com>\n\n* fix(plugin): address review findings\n\nCo-Authored-By: Claude Fable 5 <noreply@anthropic.com>\n\n---------\n\nCo-authored-by: Claude Fable 5 <noreply@anthropic.com>",
"is_bot": false,
"headline": "fix(plugin): stage root SKILL.md copy in CI so mcp-publish keeps work…",
"author_name": "chrischall",
"author_login": "chrischall",
"committed_at": "2026-07-13T21:40:03Z",
"body_truncated": true,
"is_coding_agent": true
},
{
"oid": "529ffb57effd92483305cff4a7e632e4c2815f03",
"body": "…ad (#78)\n\nClaude Code requires plugin skills entries to be directories containing SKILL.md; the root-level file reference fails to load. Move the skill to skills/gemini-mcp/ and point plugin.json at ./skills/ per the fleet standard. Update ClawHub publish / packaging / doc references to the new path.\n\nCo-authored-by: Claude Fable 5 <noreply@anthropic.com>",
"is_bot": false,
"headline": "fix(plugin): move SKILL.md into skills/ directory so plugin skills lo…",
"author_name": "chrischall",
"author_login": "chrischall",
"committed_at": "2026-07-13T21:26:29Z",
"body_truncated": false,
"is_coding_agent": true
},
{
"oid": "edd70e0f7a377847c03c3c2510f08a6494e56f0c",
"body": "Bumps [typescript](https://github.com/microsoft/TypeScript) from 6.0.3 to 7.0.2.\n- [Release notes](https://github.com/microsoft/TypeScript/releases)\n- [Commits](https://github.com/microsoft/TypeScript/commits)\n\n---\nupdated-dependencies:\n- dependency-name: typescript\n dependency-version: 7.0.2\n dep\n[…]\nrect:development\n update-type: version-update:semver-major\n...\n\nSigned-off-by: dependabot[bot] <support@github.com>\nCo-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>",
"is_bot": true,
"headline": "build(deps-dev): Bump typescript from 6.0.3 to 7.0.2 (#77)",
"author_name": "dependabot[bot]",
"author_login": "dependabot[bot]",
"committed_at": "2026-07-12T19:34:07Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "a58f1c414b0f612e1cc49a343f3479875b23f342",
"body": "Bumps the production-dependencies group with 1 update: [@chrischall/mcp-utils](https://github.com/chrischall/mcp-utils).\n\n\nUpdates `@chrischall/mcp-utils` from 0.12.0 to 0.13.0\n- [Release notes](https://github.com/chrischall/mcp-utils/releases)\n- [Changelog](https://github.com/chrischall/mcp-utils/b\n[…]\nte:semver-minor\n dependency-group: production-dependencies\n...\n\nSigned-off-by: dependabot[bot] <support@github.com>\nCo-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>",
"is_bot": true,
"headline": "build(deps): Bump @chrischall/mcp-utils (#76)",
"author_name": "dependabot[bot]",
"author_login": "dependabot[bot]",
"committed_at": "2026-07-12T19:34:01Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "b154928180eb71a4fb80c2c3458b7ca0b93999a6",
"body": "Bumps the dev-dependencies group with 3 updates: [@types/node](https://github.com/DefinitelyTyped/DefinitelyTyped/tree/HEAD/types/node), [@vitest/coverage-v8](https://github.com/vitest-dev/vitest/tree/HEAD/packages/coverage-v8) and [vitest](https://github.com/vitest-dev/vitest/tree/HEAD/packages/vit\n[…]\non-update:semver-patch\n dependency-group: dev-dependencies\n...\n\nSigned-off-by: dependabot[bot] <support@github.com>\nCo-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>",
"is_bot": true,
"headline": "build(deps-dev): Bump the dev-dependencies group with 3 updates (#75)",
"author_name": "dependabot[bot]",
"author_login": "dependabot[bot]",
"committed_at": "2026-07-12T19:33:49Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "d6a1a6b5bea062bfe2f710ad7e5984e90d14e64c",
"body": null,
"is_bot": false,
"headline": "chore(main): release 1.0.0 (#73)",
"author_name": "chrischall",
"author_login": "chrischall",
"committed_at": "2026-07-08T15:13:33Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "a7b0955fd48b3a36ad070f35722a7a532deb0bb5",
"body": "…eview #72) (#74)\n\nThe SKILL.md frontmatter description and body summary, and the README intro,\nstill framed the server as images-only (README also said 'four tools', now 8) —\nso natural-language video/music requests wouldn't trigger the skill and the\nREADME undercounted the surface. Update all three to cover image + video + music.\n\nCloses #72\n\nCo-authored-by: Claude Opus 4.8 <noreply@anthropic.com>",
"is_bot": false,
"headline": "docs: describe video/music in SKILL.md trigger + README intro (auto-r…",
"author_name": "chrischall",
"author_login": "chrischall",
"committed_at": "2026-07-08T15:10:26Z",
"body_truncated": false,
"is_coding_agent": true
},
{
"oid": "078f18d0099e432e50c0894714b9343204bbd161",
"body": "…ation (#70)\n\n* feat!: rename image tools to media-first names (gemini_image_generate/edit/set)\n\nMove the media keyword to the front of the tool name so forthcoming video and\nmusic tools slot into a consistent gemini_<media>_<action> taxonomy:\n\n- gemini_generate_image → gemini_image_generate\n- gemin\n[…]\ni_music_generate / gemini_get_result tools + workflow examples.\n\nCloses #72\n\nCo-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>\n\n---------\n\nCo-authored-by: Claude Opus 4.8 <noreply@anthropic.com>",
"is_bot": false,
"headline": "feat!: media-first tool rename + video (omni) and music (Lyria) gener…",
"author_name": "chrischall",
"author_login": "chrischall",
"committed_at": "2026-07-08T15:05:52Z",
"body_truncated": true,
"is_coding_agent": true
},
{
"oid": "78a76ba36b190438ad290bf86e396f320494507a",
"body": null,
"is_bot": false,
"headline": "chore(main): release 0.9.0 (#63)",
"author_name": "chrischall",
"author_login": "chrischall",
"committed_at": "2026-07-08T13:48:27Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "021bfff4dfb3c1e617c7fb20305cc298b831472e",
"body": "…, async fingerprint dedup, getJobResult guard) (#69)\n\n* test: cover gemini_edit_image idempotency (auto-review nit #68)\n\nCloses #68\n\nCo-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>\n\n* test: cover fingerprint-only async dedup; harden getJobResult done-fallback (auto-review nits #67)\n\n- getJo\n[…]\nue, no\n idempotency_key → second caller gets the same job_id).\n\nCloses #67\n\nCo-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>\n\n---------\n\nCo-authored-by: Claude Opus 4.8 <noreply@anthropic.com>",
"is_bot": false,
"headline": "test: land raced auto-review nits for #65/#66 (edit-image idempotency…",
"author_name": "chrischall",
"author_login": "chrischall",
"committed_at": "2026-07-08T13:43:35Z",
"body_truncated": true,
"is_coding_agent": true
},
{
"oid": "7a065b329476a21c63dc4734be088d730f9045f3",
"body": "* docs: design spec for job registry (idempotency #53 + async #52)\n\nCo-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>\n\n* feat: idempotency guard for generation calls after host timeouts\n\nWhen an MCP host times out a long generation (-32001) the server-side call\nusually completes anyway, so a b\n[…]\n_get_result registers. 272 tests pass, typecheck + build clean.\n\nCloses #52\n\nCo-authored-by: Claude Opus 4.8 <noreply@anthropic.com>\n\n---------\n\nCo-authored-by: Claude Opus 4.8 <noreply@anthropic.com>",
"is_bot": false,
"headline": "feat: idempotency guard for generation calls after host timeouts (#65)",
"author_name": "chrischall",
"author_login": "chrischall",
"committed_at": "2026-07-08T13:30:11Z",
"body_truncated": true,
"is_coding_agent": true
},
{
"oid": "59463f8ecf44112522c4b7bbc8f57235b00db12b",
"body": "…et/interact wiring (#64)\n\n- timeoutRiskHint: delimiter-anchor the Pro-model match\n (/(?:^|[-_./])pro(?:[-_./]|$)/i) so ids like gemini-3.1-prototype-image\n and gemini-3.1-flash-proxy no longer false-positive, while\n gemini-3-pro-image / nano-banana-pro still flag.\n- Add timeout_risk wiring tests\n[…]\nemini_interact (4K vs\n default) — previously only gemini_generate_image was covered.\n\nCloses #62. All 256 tests pass, typecheck + build clean.\n\nCo-authored-by: Claude Opus 4.8 <noreply@anthropic.com>",
"is_bot": false,
"headline": "test: address auto-review nits — anchor pro-model regex, cover edit/s…",
"author_name": "chrischall",
"author_login": "chrischall",
"committed_at": "2026-07-08T13:00:56Z",
"body_truncated": true,
"is_coding_agent": true
},
{
"oid": "cba7651a3ad52ce1d9b3aeea552c3949d0d1b41a",
"body": "Long Pro/4K generations trip a host's tools/call timeout (-32001). On\nClaude Desktop the ceiling is ~30s, non-configurable, and it ignores our\nprogress heartbeat (the bundled MCP client's hard limit does not reset on\nnotifications/progress) — so no server change can lift it. Two additions\nmake the s\n[…]\nage still lands on disk (+ interact\n sidecar) when a host bails. Fast configs get no field.\n\nTDD; all 252 tests pass, typecheck + build clean.\n\nCo-authored-by: Claude Opus 4.8 <noreply@anthropic.com>",
"is_bot": false,
"headline": "feat: surface host-timeout diagnostics and steer slow configs (#61)",
"author_name": "chrischall",
"author_login": "chrischall",
"committed_at": "2026-07-08T12:11:02Z",
"body_truncated": true,
"is_coding_agent": true
},
{
"oid": "277dc8477c555032f5becde108bd824f6360ac87",
"body": null,
"is_bot": false,
"headline": "chore(main): release 0.8.0 (#50)",
"author_name": "chrischall",
"author_login": "chrischall",
"committed_at": "2026-07-07T15:08:04Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "4a6e8288e7178814eb79f345c0d476be2b10a959",
"body": "Two-minor jump from 0.10.3 (the oldest pin in the fleet). This rolls up\nthe 0.11.0 security fixes — the ReDoS hardening and secret-redaction\nimprovements — plus the wave-2 helper additions, and lands on 0.12.0\n(fetchproxy detail hook + scrape subpath export).\n\nPin-only for this repo: no bridge healt\n[…]\nk (direct fetch client) and\nno scrape helpers in use, so no code adoption applies. Build and full\ntest suite (243 tests) pass clean on the jump.\n\nCo-authored-by: Claude Fable 5 <noreply@anthropic.com>",
"is_bot": false,
"headline": "fix: bump @chrischall/mcp-utils to 0.12.0 (#58)",
"author_name": "chrischall",
"author_login": "chrischall",
"committed_at": "2026-07-07T14:31:30Z",
"body_truncated": true,
"is_coding_agent": true
},
{
"oid": "4c7abe41d9a78b032bdfbffe4bff25eee30c402d",
"body": "Add the fleet-standard exception clarifying that bumping a\nchrischall-owned package (`@chrischall/mcp-utils`, `@chrischall/realty-core`,\n`@fetchproxy/server`) should be labeled `enhancement`/`bug` with a\n`feat:`/`fix:` prefix rather than `dependencies`/`chore:`, so the bump\ndrives a release-please version bump instead of being hidden under\nDependencies.\n\nCo-authored-by: Claude Fable 5 <noreply@anthropic.com>",
"is_bot": false,
"headline": "docs: document first-party dependency-bump label exception (#60)",
"author_name": "chrischall",
"author_login": "chrischall",
"committed_at": "2026-07-07T14:19:22Z",
"body_truncated": false,
"is_coding_agent": true
},
{
"oid": "816c699c82105f96663df9b0f0b1847ac87062a1",
"body": "…tinue test (#57)\n\n- src/tools/shared.ts: the sharedImageSchema JSDoc block had drifted above\n MODEL_CHOICE_GUIDE's own comment, leaving sharedImageSchema undocumented.\n Move it back to sit directly above sharedImageSchema.\n- src/tools/interact.ts: export a test-only __resetInteractSessionForTest(\n[…]\nn\n memory in beforeEach so the \"no previous interaction\" test no longer relies\n on module-load state; verified green under --sequence.shuffle.\n\nCo-authored-by: Claude Fable 5 <noreply@anthropic.com>",
"is_bot": false,
"headline": "fix: restore sharedImageSchema JSDoc + order-independent interact-con…",
"author_name": "chrischall",
"author_login": "chrischall",
"committed_at": "2026-07-07T12:41:42Z",
"body_truncated": true,
"is_coding_agent": true
},
{
"oid": "e19a15217b542cfac863cacc3d66b5cf45adf76c",
"body": "* fix: confirm-gate local-file image inputs before upload to Gemini\n\nThe generation tools read local file bytes (resolveInputPath /\nreadImageAsInline) from `images` / `master_images` / `video_path` and\nship them to Google. A prompt-injected local path (e.g. ~/.ssh/id_rsa)\ncould exfiltrate a secret w\n[…]\nhe existing 'gemini_interact without\nconfirm (video input)' test.\n\nCloses #56\n\nCo-Authored-By: Claude Fable 5 <noreply@anthropic.com>\n\n---------\n\nCo-authored-by: Claude Fable 5 <noreply@anthropic.com>",
"is_bot": false,
"headline": "fix: confirm-gate local-file image inputs before upload to Gemini (#55)",
"author_name": "chrischall",
"author_login": "chrischall",
"committed_at": "2026-07-07T08:25:51Z",
"body_truncated": true,
"is_coding_agent": true
},
{
"oid": "b20edc56f39c047bedb047373f315f59a2938bb4",
"body": "…tion-id sidecar for timeout recovery (#54)\n\n- resolveTimeoutMs(): per-call timeout_ms → $GEMINI_TIMEOUT_MS → 120s for 4K → 60s,\n resolved at request time; GeminiClient memoizes a createApiClient pair per timeout.\n- timeout_ms param on all four generation tools.\n- withProgressHeartbeat(): notificat\n[…]\nocs: README, CLAUDE.md, manifest.json (gemini_timeout_ms user_config).\n\n\nClaude-Session: https://claude.ai/code/session_01NHCXZrzzTWocRJZG1esphz\n\nCo-authored-by: Claude Fable 5 <noreply@anthropic.com>",
"is_bot": false,
"headline": "feat(timeout): configurable timeouts, progress heartbeat, and interac…",
"author_name": "chrischall",
"author_login": "chrischall",
"committed_at": "2026-07-06T18:43:13Z",
"body_truncated": true,
"is_coding_agent": true
},
{
"oid": "3314990b8056e604cb7e339dc43286effa8d117f",
"body": "…en job) (#51)\n\nUn-armed PRs now block via a yellow 'ci-gated: pending' commit status\ninstead of a red failing 'ci / ci' job; the ruleset flips to require\nthe ci-gated context right after this merges. Red check runs then only\never mean real failures.\n\nCo-authored-by: Claude Fable 5 <noreply@anthropic.com>",
"is_bot": false,
"headline": "ci: switch the deferred-CI gate to status mode (pending ci-gated, gre…",
"author_name": "chrischall",
"author_login": "chrischall",
"committed_at": "2026-07-06T14:44:26Z",
"body_truncated": false,
"is_coding_agent": true
},
{
"oid": "1d20cead9f01be0a48c539be072374a58a2cc804",
"body": "chrischall/workflows#21 changed the auto-review pipeline: a pass\nverdict whose structured output lists nits now opens/updates the\nper-PR auto-review-followup issue too (previously warn/fail only).\nUpdate the conventions doc to match.\n\nCo-authored-by: Claude Fable 5 <noreply@anthropic.com>",
"is_bot": false,
"headline": "docs(claude): follow-up issues now also open on pass-with-nits (#49)",
"author_name": "chrischall",
"author_login": "chrischall",
"committed_at": "2026-07-06T14:16:24Z",
"body_truncated": false,
"is_coding_agent": true
},
{
"oid": "c0a50b3932582026bd4c03737b7acdec878ff943",
"body": null,
"is_bot": false,
"headline": "chore(main): release 0.7.2 (#47)",
"author_name": "chrischall",
"author_login": "chrischall",
"committed_at": "2026-07-06T14:13:45Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "a998545150ca1dfe6721ab8ac8506f4ff3e2a947",
"body": "…esolve() calls (#48)\n\nAddresses the two nits from PR #46's auto-review. The onWritten\nresolve() was a true no-op (writeImage already returns resolved\nabsolute paths) — removed. The resolve() around resolveImagePath was\nNOT a no-op: with a relative GEMINI_INPUT_DIR, resolveInputPath\nreturned join(in\n[…]\narison.\nFixed at the source instead — resolveInputPath now always returns an\nabsolute path — making both call-site resolves genuinely redundant.\n\nCo-authored-by: Claude Fable 5 <noreply@anthropic.com>",
"is_bot": false,
"headline": "fix(images): always resolve input paths to absolute; drop redundant r…",
"author_name": "chrischall",
"author_login": "chrischall",
"committed_at": "2026-07-06T14:10:26Z",
"body_truncated": true,
"is_coding_agent": true
},
{
"oid": "f4bdc2d14689d280802fa2da298744a3eff17666",
"body": "…in schema and hint (#46)\n\nChained gemini_interact calls were observed re-attaching the previous\nturn's output file via `images` alongside `previous_interaction_id`.\nThe interaction state already contains that image, so re-sending it\ndouble-conditions the model and anchors it against the requested e\n[…]\nutput is legitimate.\n\n`emit()` gains an optional `onWritten` callback so the tool can record\nthe paths it writes without parsing its own result.\n\nCo-authored-by: Claude Fable 5 <noreply@anthropic.com>",
"is_bot": false,
"headline": "fix(interact): drop re-attached prior outputs on chained calls; warn …",
"author_name": "chrischall",
"author_login": "chrischall",
"committed_at": "2026-07-06T14:02:44Z",
"body_truncated": true,
"is_coding_agent": true
},
{
"oid": "aa66948a3a8af4fad08a7ac013686a96f96180e7",
"body": null,
"is_bot": false,
"headline": "chore(main): release 0.7.1 (#45)",
"author_name": "chrischall",
"author_login": "chrischall",
"committed_at": "2026-07-06T12:32:25Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "c2f3a8af051a86c2c184b947ec3597058973a265",
"body": "…tually consistent (#44)\n\nA live session hit repeated 404 not_found errors passing a valid\nprevious_interaction_id. Diagnosis against the real failing id ruled out\nthe suspects one by one: the API key matched (same fingerprint in the\nsession config and .env), the id existed (GET returned it, status\n\n[…]\nhe last output\nimage via `images`. Unchained 404s pass through untouched.\n\nVerified shapes and the diagnosis are recorded in docs/GEMINI-API.md.\n\nCo-authored-by: Claude Fable 5 <noreply@anthropic.com>",
"is_bot": false,
"headline": "fix(client): retry chained interact 404s — interactions store is even…",
"author_name": "chrischall",
"author_login": "chrischall",
"committed_at": "2026-07-06T07:50:31Z",
"body_truncated": true,
"is_coding_agent": true
},
{
"oid": "4e56b833e036e453217e44bf2cfedebd89c180b5",
"body": null,
"is_bot": false,
"headline": "chore(main): release 0.7.0 (#41)",
"author_name": "chrischall",
"author_login": "chrischall",
"committed_at": "2026-07-06T07:07:54Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "8f82bda20f76d792a00a8e31937bb32c6bbd6849",
"body": "…ng playbook (#43)\n\nImplements the newly documented search_types field on the google_search\ngrounding tool (Interactions API), live-verified 2026-07-06:\n\n- gemini_interact accepts search_types: [\"web_search\",\"image_search\"]\n (implies google_search). image_search (gemini-3.1-flash-image only)\n uses\n[…]\napes plus\n documented-but-unimplemented capabilities (response_format array for\n interleaved text+image, Batch API, url_citation annotations).\n\nCo-authored-by: Claude Fable 5 <noreply@anthropic.com>",
"is_bot": false,
"headline": "feat(interact): image_search grounding via search_types, plus prompti…",
"author_name": "chrischall",
"author_login": "chrischall",
"committed_at": "2026-07-06T07:02:34Z",
"body_truncated": true,
"is_coding_agent": true
},
{
"oid": "a24fb24849793558be70397df242b177b6ad432d",
"body": "…GA (#42)\n\nVerified live against Google's current docs and API (2026-07-06):\n\n- The Interactions API is now generally available; the beta-era\n Api-Revision: 2026-05-20 header is no longer required (requests succeed\n with and without it) and current docs no longer mention it. Stop sending\n it so t\n[…]\n candidate: the google_search tool now documents an optional\nsearch_types: [\"web_search\",\"image_search\"] field (noted in docs, not\nimplemented).\n\nCo-authored-by: Claude Fable 5 <noreply@anthropic.com>",
"is_bot": false,
"headline": "fix(client): drop obsolete Api-Revision header — Interactions API is …",
"author_name": "chrischall",
"author_login": "chrischall",
"committed_at": "2026-07-06T06:40:35Z",
"body_truncated": true,
"is_coding_agent": true
},
{
"oid": "529b404a575b372c10096758b5185baa7689c148",
"body": "…ast, default to gemini-3.1-flash-image (#39)\n\nAgents iterating on an image were re-running gemini_edit_image (re-uploading\nthe full image each round) instead of chaining the multi-turn Interactions\nAPI. Make the multi-turn path discoverable and cheap to use:\n\n- gemini_interact description now leads\n[…]\nlow-up: server-level MCP instructions need an `instructions` option in\n@chrischall/mcp-utils createMcpServer/runMcp before they can be set here.\n\nCo-authored-by: Claude Fable 5 <noreply@anthropic.com>",
"is_bot": false,
"headline": "feat(tools): steer iterative edits to gemini_interact, add continue_l…",
"author_name": "chrischall",
"author_login": "chrischall",
"committed_at": "2026-07-06T06:32:01Z",
"body_truncated": true,
"is_coding_agent": true
},
{
"oid": "9b85815ddfc1a81103bc8a7e59d9e46a0f9b76c4",
"body": "* chore(main): release 0.6.1\n\n* fix: restore @chrischall/mcp-utils 0.10.5 in lockfile (stale release-please snapshot)",
"is_bot": false,
"headline": "chore(main): release 0.6.1 (#26)",
"author_name": "chrischall",
"author_login": "chrischall",
"committed_at": "2026-07-05T23:00:00Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "94a230b2213dc3596cf2bcd8e543f38af8d9ff3f",
"body": "Bumps the production-dependencies group with 1 update: [@chrischall/mcp-utils](https://github.com/chrischall/mcp-utils).\n\n\nUpdates `@chrischall/mcp-utils` from 0.10.4 to 0.10.5\n- [Release notes](https://github.com/chrischall/mcp-utils/releases)\n- [Changelog](https://github.com/chrischall/mcp-utils/b\n[…]\nte:semver-patch\n dependency-group: production-dependencies\n...\n\nSigned-off-by: dependabot[bot] <support@github.com>\nCo-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>",
"is_bot": true,
"headline": "build(deps): Bump @chrischall/mcp-utils (#37)",
"author_name": "dependabot[bot]",
"author_login": "dependabot[bot]",
"committed_at": "2026-07-05T19:33:29Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "5d92cb900da58728fa19ae723322ad0e63fd86e9",
"body": "Bumps the dev-dependencies group with 1 update: [@types/node](https://github.com/DefinitelyTyped/DefinitelyTyped/tree/HEAD/types/node).\n\n\nUpdates `@types/node` from 26.0.1 to 26.1.0\n- [Release notes](https://github.com/DefinitelyTyped/DefinitelyTyped/releases)\n- [Commits](https://github.com/Definite\n[…]\non-update:semver-minor\n dependency-group: dev-dependencies\n...\n\nSigned-off-by: dependabot[bot] <support@github.com>\nCo-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>",
"is_bot": true,
"headline": "build(deps-dev): Bump @types/node in the dev-dependencies group (#36)",
"author_name": "dependabot[bot]",
"author_login": "dependabot[bot]",
"committed_at": "2026-07-05T19:33:20Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "2211756bceb1a95774cd2105381cdb9f0d86612c",
"body": "Bumps the dev-dependencies group with 1 update: [@types/node](https://github.com/DefinitelyTyped/DefinitelyTyped/tree/HEAD/types/node).\n\n\nUpdates `@types/node` from 26.0.0 to 26.0.1\n- [Release notes](https://github.com/DefinitelyTyped/DefinitelyTyped/releases)\n- [Commits](https://github.com/Definite\n[…]\non-update:semver-patch\n dependency-group: dev-dependencies\n...\n\nSigned-off-by: dependabot[bot] <support@github.com>\nCo-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>",
"is_bot": true,
"headline": "build(deps-dev): Bump @types/node in the dev-dependencies group (#35)",
"author_name": "dependabot[bot]",
"author_login": "dependabot[bot]",
"committed_at": "2026-06-28T19:33:09Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "729c5570b9bb0b7ba1005edd4ddcd0991ff4bc69",
"body": "Bumps [@types/node](https://github.com/DefinitelyTyped/DefinitelyTyped/tree/HEAD/types/node) from 25.9.3 to 26.0.0.\n- [Release notes](https://github.com/DefinitelyTyped/DefinitelyTyped/releases)\n- [Commits](https://github.com/DefinitelyTyped/DefinitelyTyped/commits/HEAD/types/node)\n\n---\nupdated-depe\n[…]\nrect:development\n update-type: version-update:semver-major\n...\n\nSigned-off-by: dependabot[bot] <support@github.com>\nCo-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>",
"is_bot": true,
"headline": "build(deps-dev): Bump @types/node from 25.9.3 to 26.0.0 (#34)",
"author_name": "dependabot[bot]",
"author_login": "dependabot[bot]",
"committed_at": "2026-06-21T19:33:39Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "a86e5a06aa7c76872662e119e8f1a31392260641",
"body": "Bumps the production-dependencies group with 1 update: [@chrischall/mcp-utils](https://github.com/chrischall/mcp-utils).\n\n\nUpdates `@chrischall/mcp-utils` from 0.10.3 to 0.10.4\n- [Release notes](https://github.com/chrischall/mcp-utils/releases)\n- [Changelog](https://github.com/chrischall/mcp-utils/b\n[…]\nte:semver-patch\n dependency-group: production-dependencies\n...\n\nSigned-off-by: dependabot[bot] <support@github.com>\nCo-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>",
"is_bot": true,
"headline": "build(deps): Bump @chrischall/mcp-utils (#33)",
"author_name": "dependabot[bot]",
"author_login": "dependabot[bot]",
"committed_at": "2026-06-21T19:33:33Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "78761e3c33e6923d10c13148931d1fe2ec706e43",
"body": "Bumps the dev-dependencies group with 2 updates: [@vitest/coverage-v8](https://github.com/vitest-dev/vitest/tree/HEAD/packages/coverage-v8) and [vitest](https://github.com/vitest-dev/vitest/tree/HEAD/packages/vitest).\n\n\nUpdates `@vitest/coverage-v8` from 4.1.8 to 4.1.9\n- [Release notes](https://gith\n[…]\non-update:semver-patch\n dependency-group: dev-dependencies\n...\n\nSigned-off-by: dependabot[bot] <support@github.com>\nCo-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>",
"is_bot": true,
"headline": "build(deps-dev): Bump the dev-dependencies group with 2 updates (#32)",
"author_name": "dependabot[bot]",
"author_login": "dependabot[bot]",
"committed_at": "2026-06-21T19:33:22Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "93cd3280e45dfa08f978ee326f7f29d71c10c077",
"body": "Bumps [actions/checkout](https://github.com/actions/checkout) from 6 to 7.\n- [Release notes](https://github.com/actions/checkout/releases)\n- [Changelog](https://github.com/actions/checkout/blob/main/CHANGELOG.md)\n- [Commits](https://github.com/actions/checkout/compare/v6...v7)\n\n---\nupdated-dependenc\n[…]\nirect:production\n update-type: version-update:semver-major\n...\n\nSigned-off-by: dependabot[bot] <support@github.com>\nCo-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>",
"is_bot": true,
"headline": "build(deps): Bump actions/checkout from 6 to 7 (#31)",
"author_name": "dependabot[bot]",
"author_login": "dependabot[bot]",
"committed_at": "2026-06-21T19:33:06Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "6643da2437309d853286050d8473cebdd2a140ec",
"body": "Bumps [hono](https://github.com/honojs/hono) from 4.12.23 to 4.12.26.\n- [Release notes](https://github.com/honojs/hono/releases)\n- [Commits](https://github.com/honojs/hono/compare/v4.12.23...v4.12.26)\n\n---\nupdated-dependencies:\n- dependency-name: hono\n dependency-version: 4.12.26\n dependency-type: indirect\n...\n\nSigned-off-by: dependabot[bot] <support@github.com>\nCo-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>",
"is_bot": true,
"headline": "build(deps): Bump hono from 4.12.23 to 4.12.26 (#30)",
"author_name": "dependabot[bot]",
"author_login": "dependabot[bot]",
"committed_at": "2026-06-20T04:03:19Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "6f57b7a1d77bd6b908aff30f4869e4593fcb595f",
"body": "Bumps the production-dependencies group with 1 update: [@chrischall/mcp-utils](https://github.com/chrischall/mcp-utils).\n\n\nUpdates `@chrischall/mcp-utils` from 0.7.0 to 0.10.3\n- [Release notes](https://github.com/chrischall/mcp-utils/releases)\n- [Changelog](https://github.com/chrischall/mcp-utils/bl\n[…]\nte:semver-minor\n dependency-group: production-dependencies\n...\n\nSigned-off-by: dependabot[bot] <support@github.com>\nCo-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>",
"is_bot": true,
"headline": "build(deps): Bump @chrischall/mcp-utils (#28)",
"author_name": "dependabot[bot]",
"author_login": "dependabot[bot]",
"committed_at": "2026-06-15T22:16:45Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "bc0875c671f728fcb9ed97f9d69d97b8d38713e1",
"body": "… (#29)\n\nBump the stale TL;DR version label (v0.5.0 → v0.6.0; repo is at 0.6.0),\nupdate the merge paragraph to reflect that pass OR warn arms ready-to-merge\nwhile warn/fail open a follow-up issue and only fail blocks, and add the\nauto-review follow-up convention from chrischall/workflows#7.\n\nCo-authored-by: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
"is_bot": false,
"headline": "docs: refresh CLAUDE.md and document auto-review follow-up convention…",
"author_name": "chrischall",
"author_login": "chrischall",
"committed_at": "2026-06-15T11:10:46Z",
"body_truncated": false,
"is_coding_agent": true
},
{
"oid": "430d8032a55173780a88383a18d094d9eebd4d2b",
"body": "Bumps the dev-dependencies group with 2 updates: [@types/node](https://github.com/DefinitelyTyped/DefinitelyTyped/tree/HEAD/types/node) and [esbuild](https://github.com/evanw/esbuild).\n\n\nUpdates `@types/node` from 25.9.2 to 25.9.3\n- [Release notes](https://github.com/DefinitelyTyped/DefinitelyTyped/\n[…]\non-update:semver-patch\n dependency-group: dev-dependencies\n...\n\nSigned-off-by: dependabot[bot] <support@github.com>\nCo-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>",
"is_bot": true,
"headline": "build(deps-dev): Bump the dev-dependencies group with 2 updates (#27)",
"author_name": "dependabot[bot]",
"author_login": "dependabot[bot]",
"committed_at": "2026-06-14T19:33:36Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "6c222e2e6d91bb31929f05257c6536477561599d",
"body": "Co-authored-by: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
"is_bot": false,
"headline": "docs: require Conventional Commit PR titles for release-please (#25)",
"author_name": "chrischall",
"author_login": "chrischall",
"committed_at": "2026-06-14T02:44:38Z",
"body_truncated": false,
"is_coding_agent": true
},
{
"oid": "84be89e7785d6f60ba15d69c2fcb2a4d58a31b9b",
"body": null,
"is_bot": false,
"headline": "chore(main): release 0.6.0 (#17)",
"author_name": "chrischall",
"author_login": "chrischall",
"committed_at": "2026-06-13T00:53:36Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "c257ee0dea6b3d6ff1b8478aad5fdeda6b68464c",
"body": "Thin stubs replace the vendored auto-review/auto-merge/CI/release workflows.\nPipeline source: https://github.com/chrischall/workflows",
"is_bot": false,
"headline": "ci: convert to chrischall/workflows reusable pipeline (#23)",
"author_name": "chrischall",
"author_login": "chrischall",
"committed_at": "2026-06-12T19:44:38Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "1daa5637210e884dad8f595ea503260aba765a71",
"body": "…o-image (#22)\n\nAdds a `video_path` param to `gemini_generate_image` and `gemini_interact`,\nalongside the existing YouTube-only `video_url`. A local video is uploaded to\nthe Gemini Files API (resumable protocol), polled PROCESSING→ACTIVE, and its\n`files/<id>` uri is passed as the video reference.\n\n-\n[…]\n finalize vs unwrapped poll, 48h expirationTime, generate +\ninteract both 200 with the uploaded uri) and pinned in docs/GEMINI-API.md.\n\nFixes #8\n\nCo-authored-by: Claude Fable 5 <noreply@anthropic.com>",
"is_bot": false,
"headline": "feat: local video input via video_path (Files API upload) for video-t…",
"author_name": "chrischall",
"author_login": "chrischall",
"committed_at": "2026-06-12T15:44:28Z",
"body_truncated": true,
"is_coding_agent": true
},
{
"oid": "4bb2a22a17386960fba4a53f4f398e513f73f36e",
"body": "…sh (#21)\n\nclaude-code-action only supports track_progress for opened/synchronize/\nready_for_review/reopened pull_request actions and exits 1 on 'labeled'\n— which is how the release-ready gate and the review-with-opus\nforce-rerun trigger reviews. Both label paths crashed before reviewing\nanything. Same fix as gogcli-mcp#103.\n\nCo-authored-by: Claude Opus 4.8 <noreply@anthropic.com>",
"is_bot": false,
"headline": "ci: disable track_progress on labeled-event reviews so they don't cra…",
"author_name": "chrischall",
"author_login": "chrischall",
"committed_at": "2026-06-12T13:53:29Z",
"body_truncated": false,
"is_coding_agent": true
},
{
"oid": "d310f5a8ebe98cbc6a8d047fccd82ea08a93092f",
"body": "The labeled-guard in the bot clause wrongly skipped CI on bot PR label\nevents. Apply the upstream curtaincall#86 review fix: unconditional\nbot bypass.",
"is_bot": false,
"headline": "fix: bot PRs bypass the CI gate unconditionally (#20)",
"author_name": "chrischall",
"author_login": "chrischall",
"committed_at": "2026-06-11T15:21:16Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "566963ca2a63e1f66852bc5a3fdfc43c9907d0fb",
"body": "… PRs (#19)\n\nFleet rollout of the curtaincall PR-workflow economy\n(chrischall/curtaincall#84 + chrischall/curtaincall#86): CI is the LAST\ngate, not a parallel cost.\n\n- Human PRs: CI runs only once auto-review passes and arms\n `ready-to-merge` — the label event fires the run, and pushes to an\n arme\n[…]\nlease-ready` label,\n the ship signal. Labeling it runs both; pass arms `ready-to-merge`.\n- workflow_call / push triggers fall through unharmed.\n\nCo-authored-by: Claude Fable 5 <noreply@anthropic.com>",
"is_bot": false,
"headline": "ci: defer CI to ready-to-merge arming; release-ready gate for release…",
"author_name": "chrischall",
"author_login": "chrischall",
"committed_at": "2026-06-11T15:06:31Z",
"body_truncated": true,
"is_coding_agent": true
},
{
"oid": "b91e5bde1bb7da5771cf027256942bda5687e1e3",
"body": "package.json has declared MIT since first publish, but the license text\nwas never in the repo — GitHub showed no license and npm tarballs\ncarried only the metadata field. Single-package repo, so the root\nLICENSE is auto-bundled into the npm tarball by npm itself.\n\nCo-authored-by: Claude Opus 4.8 <noreply@anthropic.com>",
"is_bot": false,
"headline": "docs: add MIT LICENSE file and README badges (#18)",
"author_name": "chrischall",
"author_login": "chrischall",
"committed_at": "2026-06-11T14:20:50Z",
"body_truncated": false,
"is_coding_agent": true
},
{
"oid": "036836e407f9d0dd4ceedc9849bf4ee29f43af33",
"body": "Add a cohort-quality CLAUDE.md for gemini-mcp, closing the consistency gap\nwith the rest of the fleet (every other MCP has one). Covers the TL;DR,\nenvironment, architecture + custom call() client, tool surface, conventions,\nquirks (non-Bearer x-goog-api-key auth, model-in-path, v1beta pin, Api-Revis\n[…]\nd, premium-account\n429 limit:0), versioning/release-please flow, and PR workflow. Every claim\nverified against source. Doc-only; no code change.\n\nCo-authored-by: Claude Fable 5 <noreply@anthropic.com>",
"is_bot": false,
"headline": "docs: add CLAUDE.md (#16)",
"author_name": "chrischall",
"author_login": "chrischall",
"committed_at": "2026-06-10T02:27:55Z",
"body_truncated": true,
"is_coding_agent": true
},
{
"oid": "9b9cf9a0bb09c53a1d35d5c290451bcf086bdafb",
"body": null,
"is_bot": false,
"headline": "chore(main): release 0.5.0 (#15)",
"author_name": "chrischall",
"author_login": "chrischall",
"committed_at": "2026-06-10T02:09:13Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "4e8719127a150658570f2e9a21a3c6cfdea76084",
"body": "…etry) (#14)\n\nBump @chrischall/mcp-utils to ^0.7.0 and replace the hand-rolled fetches\nin GeminiClient.call() and interact() — which had no timeout, no 429\nretry, and no redacted error formatting — with createApiClient, now\npossible because 0.7.0's tokenHeader option puts the key in a custom\nheader:\n[…]\nout is left as-is: the client-level\n429 retry now covers the burst, and a throttle would not be a trivial\ninsertion around the shared singleton.\n\nCo-authored-by: Claude Fable 5 <noreply@anthropic.com>",
"is_bot": false,
"headline": "feat: migrate both Gemini paths to the shared client (timeout + 429 r…",
"author_name": "chrischall",
"author_login": "chrischall",
"committed_at": "2026-06-09T21:17:14Z",
"body_truncated": true,
"is_coding_agent": true
},
{
"oid": "8ef110cfbfbb8173d0d1b074c126f95adac17e34",
"body": null,
"is_bot": false,
"headline": "chore(main): release 0.4.0 (#10)",
"author_name": "chrischall",
"author_login": "chrischall",
"committed_at": "2026-06-08T14:42:19Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "aaa761fafb1a46ea1ba35e77695dbd5743dc78de",
"body": "* feat(images): add resolveImagePath with GEMINI_INPUT_DIR fallback\n\nIntroduces `resolveImagePath(p)` which checks absolute path, then\n`GEMINI_INPUT_DIR/p`, then cwd-relative, throwing a helpful McpToolError\nwith a hint when none match. `readImageAsInline` now calls it first so\nevery path-based too\n[…]\nwith the built-in\nfrom_clipboard flag; adds GEMINI_INPUT_DIR to env tables, .mcp.json, server.json,\nand manifest.json user_config.\n\n---------\n\nCo-authored-by: Claude Sonnet 4.6 <noreply@anthropic.com>",
"is_bot": false,
"headline": "feat: GEMINI_INPUT_DIR resolution + from_clipboard image ingestion (#12)",
"author_name": "chrischall",
"author_login": "chrischall",
"committed_at": "2026-06-08T14:35:43Z",
"body_truncated": true,
"is_coding_agent": true
},
{
"oid": "06ab419c3fc37b82e5d98ba9bca934fcf625195b",
"body": "…ages (#11)\n\nWhen the user copies an image to the system clipboard (not just pastes inline),\nthe assistant can extract the real bytes via osascript «class PNGf», downscale\nwith sips, and pass the path to images[]. Verified live.",
"is_bot": false,
"headline": "docs(skill): add verified macOS clipboard workaround for reference im…",
"author_name": "chrischall",
"author_login": "chrischall",
"committed_at": "2026-06-08T14:11:34Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "e441f878a223ae0d85c892bf887ef7716949effa",
"body": "…le) (#9)\n\nA previous note wrongly suggested passing a chat-pasted image via images_base64.\nA paste reaches the model as a vision block only — the original bytes are never\nexposed and the host doesn't write the file to disk, so neither images (no path)\nnor images_base64 (can't reconstruct bytes from a vision rendering) works. Clarify\nthat the user must supply a path / data-URI-as-text / URL; it's a host limitation.\n\nCo-authored-by: Claude Opus 4.8 <noreply@anthropic.com>",
"is_bot": false,
"headline": "docs(skill): correct chat-pasted-image guidance (bytes aren't reachab…",
"author_name": "chrischall",
"author_login": "chrischall",
"committed_at": "2026-06-08T14:04:10Z",
"body_truncated": false,
"is_coding_agent": true
},
{
"oid": "1484d2e66d13c123aea17752340a5b2bd814b1d9",
"body": null,
"is_bot": false,
"headline": "chore(main): release 0.3.0 (#5)",
"author_name": "chrischall",
"author_login": "chrischall",
"committed_at": "2026-06-08T13:09:39Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "1b68773712e102a86faf4740b8a04aa51e84df75",
"body": "* docs: pin verified Google Search grounding + video-to-image shapes (both APIs)\n\n* feat(client): add Google Search grounding and video URL to generate/interact\n\nGenerateOpts gains googleSearch (adds tools:[{google_search:{}}] top-level)\nand videoUrl (pushes a file_data part alongside text/image par\n[…]\n\nsearch_suggestions), so queries-only; documented in GEMINI-API.md + SKILL.\n\nCo-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>\n\n---------\n\nCo-authored-by: Claude Opus 4.8 <noreply@anthropic.com>",
"is_bot": false,
"headline": "feat: Google Search grounding + video-to-image (#7)",
"author_name": "chrischall",
"author_login": "chrischall",
"committed_at": "2026-06-08T13:06:34Z",
"body_truncated": true,
"is_coding_agent": true
},
{
"oid": "5a71937aa0f1170b3c7d471a45371e414280a9fa",
"body": "… (#6)\n\n* docs: pin verified Interactions API + generateContent 512/thinkingConfig/TEXT shapes\n\n* feat: add 512 (Flash-only 0.5K) to IMAGE_SIZES enum\n\nVerified 2026-06-08 against gemini-3.1-flash-image — accepted at the API level.\nUpdates IMAGE_SIZES const, z.enum in sharedImageSchema describe text,\n[…]\nlike the\ngenerateContent error path ('Gemini Interactions API 400: ...').\n\nCo-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>\n\n---------\n\nCo-authored-by: Claude Sonnet 4.6 <noreply@anthropic.com>",
"is_bot": false,
"headline": "feat: Interactions API multi-turn + thinking_level, 512, text capture…",
"author_name": "chrischall",
"author_login": "chrischall",
"committed_at": "2026-06-08T12:20:02Z",
"body_truncated": true,
"is_coding_agent": true
},
{
"oid": "09d28445b8384fa9a05a4674e00cc00f981124c5",
"body": "* feat(A): magic-byte mime sniffing, decodeImageInput, loadImageInputs, baseName\n\n- Refactor readImageAsInline to use sniffMimeBytes (PNG/JPEG/WebP magic bytes)\n instead of extension-based detection; existing PNG test still passes.\n- Add decodeImageInput: accepts data URI (parses mime+data) or raw \n[…]\nus 4.8 <noreply@anthropic.com>\n\n* docs(skill): document image-by-value, seed, filename, and the no-edit-strength/4K/text limitations\n\n---------\n\nCo-authored-by: Claude Opus 4.8 <noreply@anthropic.com>",
"is_bot": false,
"headline": "feat: image input by value, seed, filenames, set references (#4)",
"author_name": "chrischall",
"author_login": "chrischall",
"committed_at": "2026-06-08T03:59:03Z",
"body_truncated": true,
"is_coding_agent": true
},
{
"oid": "787637ccc0b03d5f3934ba1fafc32f28bc0ed729",
"body": null,
"is_bot": false,
"headline": "chore(main): release 0.2.0 (#2)",
"author_name": "chrischall",
"author_login": "chrischall",
"committed_at": "2026-06-08T01:11:08Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "7053e8d6da8bcb769bd1f7e5927c1dc233477292",
"body": "Bumps the actions group with 1 update: [chrischall/mcp-utils](https://github.com/chrischall/mcp-utils).\n\n\nUpdates `chrischall/mcp-utils` from 0.2.1 to 0.6.0\n- [Release notes](https://github.com/chrischall/mcp-utils/releases)\n- [Changelog](https://github.com/chrischall/mcp-utils/blob/main/CHANGELOG.m\n[…]\npe: version-update:semver-minor\n dependency-group: actions\n...\n\nSigned-off-by: dependabot[bot] <support@github.com>\nCo-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>",
"is_bot": true,
"headline": "build(deps): Bump chrischall/mcp-utils in the actions group (#3)",
"author_name": "dependabot[bot]",
"author_login": "dependabot[bot]",
"committed_at": "2026-06-08T01:10:12Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "a3560d5205053e88c35f195cdff57d052ef2a15c",
"body": "* chore: scaffold gemini-mcp project\n\n* feat: version source + version-sync guard\n\n* feat: model resolution + image-model filter\n\n* feat: image disk I/O (slug, write, read, output dir)\n\n* fix: exclude imagen-* from image-model filter (verification finding)\n\nCo-Authored-By: Claude Opus 4.8 <noreply@a\n[…]\ne npm package is scoped. GitHub repo renamed back to chrischall/gemini-mcp.\n\nCo-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>\n\n---------\n\nCo-authored-by: Claude Opus 4.8 <noreply@anthropic.com>",
"is_bot": false,
"headline": "feat: initial gemini-mcp implementation (#1)",
"author_name": "chrischall",
"author_login": "chrischall",
"committed_at": "2026-06-08T01:09:06Z",
"body_truncated": true,
"is_coding_agent": true
},
{
"oid": "4b7fae272e9ee3e4bf73b3535e6866c33ec6349c",
"body": "Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>",
"is_bot": false,
"headline": "docs: gemini-mcp implementation plan",
"author_name": "Chris Hall",
"author_login": "chrischall",
"committed_at": "2026-06-07T21:01:29Z",
"body_truncated": false,
"is_coding_agent": true
},
{
"oid": "ee6672193c0350266bcc30dc22107ec65affd773",
"body": "Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>",
"is_bot": false,
"headline": "docs: gemini-mcp design spec",
"author_name": "Chris Hall",
"author_login": "chrischall",
"committed_at": "2026-06-07T20:52:34Z",
"body_truncated": false,
"is_coding_agent": true
}
],
"releases_count": 15,
"commits_last_year": 85,
"latest_release_at": "2026-07-19T16:48:49Z",
"latest_release_tag": "v1.0.3",
"releases_from_tags": false,
"days_since_last_push": 0,
"active_weeks_last_year": 7,
"days_since_latest_release": 5,
"mean_days_between_releases": 1.5
},
"community": {
"has_readme": true,
"has_license": true,
"has_description": true,
"has_contributing": false,
"health_percentage": 42,
"has_issue_template": false,
"has_code_of_conduct": false,
"has_pull_request_template": false
},
"ecosystem": {
"packages": [
{
"name": "@chrischall/gemini-mcp",
"exists": true,
"license": "MIT",
"keywords": [
"mcp",
"model-context-protocol",
"claude",
"ai",
"gemini",
"nano-banana",
"image-generation",
"image-editing",
"text-to-image",
"google-gemini"
],
"ecosystem": "npm",
"matches_repo": true,
"registry_url": "https://www.npmjs.com/package/@chrischall/gemini-mcp",
"is_deprecated": false,
"latest_version": "1.0.3",
"repository_url": "https://github.com/chrischall/gemini-mcp",
"versions_count": 16,
"total_downloads": null,
"dependents_count": null,
"deprecation_note": null,
"maintainers_count": 1,
"monthly_downloads": 2389,
"first_published_at": "2026-06-08T01:09:25.258000Z",
"latest_published_at": "2026-07-19T16:49:21.230000Z",
"latest_version_yanked": null,
"days_since_latest_publish": 5
}
]
},
"popularity": {
"forks": 0,
"stars": 0,
"watchers": 0,
"fork_history": {
"days": [],
"complete": true,
"collected": 0,
"total_forks": 0
},
"star_history": {
"days": [],
"complete": true,
"collected": 0,
"total_stars": 0,
"collected_at": null
},
"open_issues_and_prs": 2
},
"ai_readiness": {
"has_nix": false,
"example_dirs": [],
"has_llms_txt": false,
"has_dockerfile": false,
"has_mcp_signal": true,
"bootstrap_files": [],
"api_schema_files": [],
"has_devcontainer": false,
"typecheck_configs": [
"tsconfig.json"
],
"toolchain_manifests": [],
"largest_source_bytes": 49918,
"source_files_sampled": 56,
"oversized_source_files": 0,
"agent_instruction_files": [
"CLAUDE.md"
],
"agent_instruction_max_bytes": 33502
},
"dependencies": {
"manifests": [
"package.json"
],
"advisories": {
"error": null,
"scope": "published_package",
"source": "osv",
"findings": [
{
"name": "@hono/node-server",
"direct": false,
"version": "1.19.15",
"severity": "moderate",
"ecosystem": "npm",
"cvss_score": 5.9,
"advisory_ids": [
"GHSA-frvp-7c67-39w9"
],
"fixed_version": "2.0.5",
"advisory_count": 1,
"oldest_advisory_days": 3
}
],
"collected": true,
"malicious": [],
"truncated": false,
"by_severity": {
"moderate": 1
},
"advisory_count": 1,
"affected_count": 1,
"assessed_count": 97,
"malicious_count": 0,
"assessed_package": "npm:@chrischall/gemini-mcp@1.0.3",
"unassessed_count": 0,
"direct_affected_count": 0
},
"ecosystems": [
"npm"
],
"dependencies": [
{
"name": "@chrischall/mcp-utils",
"manifest": "package.json",
"ecosystem": "npm",
"version_constraint": "^0.13.0"
},
{
"name": "@modelcontextprotocol/sdk",
"manifest": "package.json",
"ecosystem": "npm",
"version_constraint": "^1.29.0"
},
{
"name": "dotenv",
"manifest": "package.json",
"ecosystem": "npm",
"version_constraint": "^17.4.0"
},
{
"name": "zod",
"manifest": "package.json",
"ecosystem": "npm",
"version_constraint": "^4.4.2"
}
],
"all_dependencies": {
"error": null,
"source": "github-sbom",
"packages": [
{
"name": "@chrischall/mcp-utils",
"direct": true,
"version": "0.13.3",
"ecosystem": "npm"
},
{
"name": "@modelcontextprotocol/sdk",
"direct": true,
"version": "1.29.0",
"ecosystem": "npm"
},
{
"name": "dotenv",
"direct": true,
"version": "17.4.2",
"ecosystem": "npm"
},
{
"name": "zod",
"direct": true,
"version": "3.25.76",
"ecosystem": "npm"
},
{
"name": "zod",
"direct": true,
"version": "4.4.3",
"ecosystem": "npm"
},
{
"name": "@babel/code-frame",
"direct": false,
"version": "8.0.0",
"ecosystem": "npm"
},
{
"name": "@babel/compat-data",
"direct": false,
"version": "8.0.0",
"ecosystem": "npm"
},
{
"name": "@babel/core",
"direct": false,
"version": "8.0.1",
"ecosystem": "npm"
},
{
"name": "@babel/generator",
"direct": false,
"version": "8.0.0",
"ecosystem": "npm"
},
{
"name": "@babel/helper-annotate-as-pure",
"direct": false,
"version": "8.0.0",
"ecosystem": "npm"
},
{
"name": "@babel/helper-compilation-targets",
"direct": false,
"version": "8.0.0",
"ecosystem": "npm"
},
{
"name": "@babel/helper-create-class-features-plugin",
"direct": false,
"version": "8.0.1",
"ecosystem": "npm"
},
{
"name": "@babel/helper-globals",
"direct": false,
"version": "8.0.0",
"ecosystem": "npm"
},
{
"name": "@babel/helper-member-expression-to-functions",
"direct": false,
"version": "8.0.0",
"ecosystem": "npm"
},
{
"name": "@babel/helper-optimise-call-expression",
"direct": false,
"version": "8.0.0",
"ecosystem": "npm"
},
{
"name": "@babel/helper-plugin-utils",
"direct": false,
"version": "8.0.1",
"ecosystem": "npm"
},
{
"name": "@babel/helper-replace-supers",
"direct": false,
"version": "8.0.1",
"ecosystem": "npm"
},
{
"name": "@babel/helper-skip-transparent-expression-wrappers",
"direct": false,
"version": "8.0.0",
"ecosystem": "npm"
},
{
"name": "@babel/helper-string-parser",
"direct": false,
"version": "7.29.7",
"ecosystem": "npm"
},
{
"name": "@babel/helper-string-parser",
"direct": false,
"version": "8.0.0",
"ecosystem": "npm"
},
{
"name": "@babel/helper-validator-identifier",
"direct": false,
"version": "7.29.7",
"ecosystem": "npm"
},
{
"name": "@babel/helper-validator-identifier",
"direct": false,
"version": "8.0.4",
"ecosystem": "npm"
},
{
"name": "@babel/helper-validator-option",
"direct": false,
"version": "8.0.0",
"ecosystem": "npm"
},
{
"name": "@babel/helpers",
"direct": false,
"version": "8.0.0",
"ecosystem": "npm"
},
{
"name": "@babel/parser",
"direct": false,
"version": "7.29.7",
"ecosystem": "npm"
},
{
"name": "@babel/parser",
"direct": false,
"version": "8.0.4",
"ecosystem": "npm"
},
{
"name": "@babel/plugin-proposal-decorators",
"direct": false,
"version": "8.0.2",
"ecosystem": "npm"
},
{
"name": "@babel/plugin-syntax-decorators",
"direct": false,
"version": "8.0.1",
"ecosystem": "npm"
},
{
"name": "@babel/runtime",
"direct": false,
"version": "7.29.7",
"ecosystem": "npm"
},
{
"name": "@babel/runtime-corejs3",
"direct": false,
"version": "7.29.7",
"ecosystem": "npm"
},
{
"name": "@babel/template",
"direct": false,
"version": "8.0.0",
"ecosystem": "npm"
},
{
"name": "@babel/traverse",
"direct": false,
"version": "8.0.4",
"ecosystem": "npm"
},
{
"name": "@babel/types",
"direct": false,
"version": "7.29.7",
"ecosystem": "npm"
},
{
"name": "@babel/types",
"direct": false,
"version": "8.0.4",
"ecosystem": "npm"
},
{
"name": "@bcoe/v8-coverage",
"direct": false,
"version": "1.0.2",
"ecosystem": "npm"
},
{
"name": "@cfworker/json-schema",
"direct": false,
"version": "4.1.1",
"ecosystem": "npm"
},
{
"name": "@chrischall/mcp-connector",
"direct": false,
"version": "1.1.0",
"ecosystem": "npm"
},
{
"name": "@cloudflare/codemode",
"direct": false,
"version": "0.4.3",
"ecosystem": "npm"
},
{
"name": "@cloudflare/kv-asset-handler",
"direct": false,
"version": "0.5.0",
"ecosystem": "npm"
},
{
"name": "@cloudflare/unenv-preset",
"direct": false,
"version": "2.16.1",
"ecosystem": "npm"
},
{
"name": "@cloudflare/vitest-pool-workers",
"direct": false,
"version": "0.18.8",
"ecosystem": "npm"
},
{
"name": "@cloudflare/workerd-darwin-64",
"direct": false,
"version": "1.20260722.1",
"ecosystem": "npm"
},
{
"name": "@cloudflare/workerd-darwin-arm64",
"direct": false,
"version": "1.20260722.1",
"ecosystem": "npm"
},
{
"name": "@cloudflare/workerd-linux-64",
"direct": false,
"version": "1.20260722.1",
"ecosystem": "npm"
},
{
"name": "@cloudflare/workerd-linux-arm64",
"direct": false,
"version": "1.20260722.1",
"ecosystem": "npm"
},
{
"name": "@cloudflare/workerd-windows-64",
"direct": false,
"version": "1.20260722.1",
"ecosystem": "npm"
},
{
"name": "@cloudflare/workers-oauth-provider",
"direct": false,
"version": "0.8.2",
"ecosystem": "npm"
},
{
"name": "@cloudflare/workers-types",
"direct": false,
"version": "4.20260702.1",
"ecosystem": "npm"
},
{
"name": "@cloudflare/workers-types",
"direct": false,
"version": "5.20260724.1",
"ecosystem": "npm"
},
{
"name": "@cspotcode/source-map-support",
"direct": false,
"version": "0.8.1",
"ecosystem": "npm"
},
{
"name": "@emnapi/core",
"direct": false,
"version": "1.11.1",
"ecosystem": "npm"
},
{
"name": "@emnapi/runtime",
"direct": false,
"version": "1.11.1",
"ecosystem": "npm"
},
{
"name": "@emnapi/wasi-threads",
"direct": false,
"version": "1.2.2",
"ecosystem": "npm"
},
{
"name": "@esbuild/aix-ppc64",
"direct": false,
"version": "0.28.1",
"ecosystem": "npm"
},
{
"name": "@esbuild/android-arm",
"direct": false,
"version": "0.28.1",
"ecosystem": "npm"
},
{
"name": "@esbuild/android-arm64",
"direct": false,
"version": "0.28.1",
"ecosystem": "npm"
},
{
"name": "@esbuild/android-x64",
"direct": false,
"version": "0.28.1",
"ecosystem": "npm"
},
{
"name": "@esbuild/darwin-arm64",
"direct": false,
"version": "0.28.1",
"ecosystem": "npm"
},
{
"name": "@esbuild/darwin-x64",
"direct": false,
"version": "0.28.1",
"ecosystem": "npm"
},
{
"name": "@esbuild/freebsd-arm64",
"direct": false,
"version": "0.28.1",
"ecosystem": "npm"
},
{
"name": "@esbuild/freebsd-x64",
"direct": false,
"version": "0.28.1",
"ecosystem": "npm"
},
{
"name": "@esbuild/linux-arm",
"direct": false,
"version": "0.28.1",
"ecosystem": "npm"
},
{
"name": "@esbuild/linux-arm64",
"direct": false,
"version": "0.28.1",
"ecosystem": "npm"
},
{
"name": "@esbuild/linux-ia32",
"direct": false,
"version": "0.28.1",
"ecosystem": "npm"
},
{
"name": "@esbuild/linux-loong64",
"direct": false,
"version": "0.28.1",
"ecosystem": "npm"
},
{
"name": "@esbuild/linux-mips64el",
"direct": false,
"version": "0.28.1",
"ecosystem": "npm"
},
{
"name": "@esbuild/linux-ppc64",
"direct": false,
"version": "0.28.1",
"ecosystem": "npm"
},
{
"name": "@esbuild/linux-riscv64",
"direct": false,
"version": "0.28.1",
"ecosystem": "npm"
},
{
"name": "@esbuild/linux-s390x",
"direct": false,
"version": "0.28.1",
"ecosystem": "npm"
},
{
"name": "@esbuild/linux-x64",
"direct": false,
"version": "0.28.1",
"ecosystem": "npm"
},
{
"name": "@esbuild/netbsd-arm64",
"direct": false,
"version": "0.28.1",
"ecosystem": "npm"
},
{
"name": "@esbuild/netbsd-x64",
"direct": false,
"version": "0.28.1",
"ecosystem": "npm"
},
{
"name": "@esbuild/openbsd-arm64",
"direct": false,
"version": "0.28.1",
"ecosystem": "npm"
},
{
"name": "@esbuild/openbsd-x64",
"direct": false,
"version": "0.28.1",
"ecosystem": "npm"
},
{
"name": "@esbuild/openharmony-arm64",
"direct": false,
"version": "0.28.1",
"ecosystem": "npm"
},
{
"name": "@esbuild/sunos-x64",
"direct": false,
"version": "0.28.1",
"ecosystem": "npm"
},
{
"name": "@esbuild/win32-arm64",
"direct": false,
"version": "0.28.1",
"ecosystem": "npm"
},
{
"name": "@esbuild/win32-ia32",
"direct": false,
"version": "0.28.1",
"ecosystem": "npm"
},
{
"name": "@esbuild/win32-x64",
"direct": false,
"version": "0.28.1",
"ecosystem": "npm"
},
{
"name": "@hono/node-server",
"direct": false,
"version": "1.19.14",
"ecosystem": "npm"
},
{
"name": "@img/colour",
"direct": false,
"version": "1.1.0",
"ecosystem": "npm"
},
{
"name": "@img/sharp-darwin-arm64",
"direct": false,
"version": "0.35.2",
"ecosystem": "npm"
},
{
"name": "@img/sharp-darwin-x64",
"direct": false,
"version": "0.35.2",
"ecosystem": "npm"
},
{
"name": "@img/sharp-freebsd-wasm32",
"direct": false,
"version": "0.35.2",
"ecosystem": "npm"
},
{
"name": "@img/sharp-libvips-darwin-arm64",
"direct": false,
"version": "1.3.1",
"ecosystem": "npm"
},
{
"name": "@img/sharp-libvips-darwin-x64",
"direct": false,
"version": "1.3.1",
"ecosystem": "npm"
},
{
"name": "@img/sharp-libvips-linux-arm",
"direct": false,
"version": "1.3.1",
"ecosystem": "npm"
},
{
"name": "@img/sharp-libvips-linux-arm64",
"direct": false,
"version": "1.3.1",
"ecosystem": "npm"
},
{
"name": "@img/sharp-libvips-linux-ppc64",
"direct": false,
"version": "1.3.1",
"ecosystem": "npm"
},
{
"name": "@img/sharp-libvips-linux-riscv64",
"direct": false,
"version": "1.3.1",
"ecosystem": "npm"
},
{
"name": "@img/sharp-libvips-linux-s390x",
"direct": false,
"version": "1.3.1",
"ecosystem": "npm"
},
{
"name": "@img/sharp-libvips-linux-x64",
"direct": false,
"version": "1.3.1",
"ecosystem": "npm"
},
{
"name": "@img/sharp-libvips-linuxmusl-arm64",
"direct": false,
"version": "1.3.1",
"ecosystem": "npm"
},
{
"name": "@img/sharp-libvips-linuxmusl-x64",
"direct": false,
"version": "1.3.1",
"ecosystem": "npm"
},
{
"name": "@img/sharp-linux-arm",
"direct": false,
"version": "0.35.2",
"ecosystem": "npm"
},
{
"name": "@img/sharp-linux-arm64",
"direct": false,
"version": "0.35.2",
"ecosystem": "npm"
},
{
"name": "@img/sharp-linux-ppc64",
"direct": false,
"version": "0.35.2",
"ecosystem": "npm"
},
{
"name": "@img/sharp-linux-riscv64",
"direct": false,
"version": "0.35.2",
"ecosystem": "npm"
},
{
"name": "@img/sharp-linux-s390x",
"direct": false,
"version": "0.35.2",
"ecosystem": "npm"
},
{
"name": "@img/sharp-linux-x64",
"direct": false,
"version": "0.35.2",
"ecosystem": "npm"
},
{
"name": "@img/sharp-linuxmusl-arm64",
"direct": false,
"version": "0.35.2",
"ecosystem": "npm"
},
{
"name": "@img/sharp-linuxmusl-x64",
"direct": false,
"version": "0.35.2",
"ecosystem": "npm"
},
{
"name": "@img/sharp-wasm32",
"direct": false,
"version": "0.35.2",
"ecosystem": "npm"
},
{
"name": "@img/sharp-webcontainers-wasm32",
"direct": false,
"version": "0.35.2",
"ecosystem": "npm"
},
{
"name": "@img/sharp-win32-arm64",
"direct": false,
"version": "0.35.2",
"ecosystem": "npm"
},
{
"name": "@img/sharp-win32-ia32",
"direct": false,
"version": "0.35.2",
"ecosystem": "npm"
},
{
"name": "@img/sharp-win32-x64",
"direct": false,
"version": "0.35.2",
"ecosystem": "npm"
},
{
"name": "@jridgewell/gen-mapping",
"direct": false,
"version": "0.3.13",
"ecosystem": "npm"
},
{
"name": "@jridgewell/resolve-uri",
"direct": false,
"version": "3.1.2",
"ecosystem": "npm"
},
{
"name": "@jridgewell/sourcemap-codec",
"direct": false,
"version": "1.5.5",
"ecosystem": "npm"
},
{
"name": "@jridgewell/trace-mapping",
"direct": false,
"version": "0.3.31",
"ecosystem": "npm"
},
{
"name": "@jridgewell/trace-mapping",
"direct": false,
"version": "0.3.9",
"ecosystem": "npm"
},
{
"name": "@napi-rs/wasm-runtime",
"direct": false,
"version": "1.1.6",
"ecosystem": "npm"
},
{
"name": "@oxc-project/types",
"direct": false,
"version": "0.139.0",
"ecosystem": "npm"
},
{
"name": "@poppinss/colors",
"direct": false,
"version": "4.1.6",
"ecosystem": "npm"
},
{
"name": "@poppinss/dumper",
"direct": false,
"version": "0.6.5",
"ecosystem": "npm"
},
{
"name": "@poppinss/exception",
"direct": false,
"version": "1.2.3",
"ecosystem": "npm"
},
{
"name": "@rolldown/binding-android-arm64",
"direct": false,
"version": "1.1.5",
"ecosystem": "npm"
},
{
"name": "@rolldown/binding-darwin-arm64",
"direct": false,
"version": "1.1.5",
"ecosystem": "npm"
},
{
"name": "@rolldown/binding-darwin-x64",
"direct": false,
"version": "1.1.5",
"ecosystem": "npm"
},
{
"name": "@rolldown/binding-freebsd-x64",
"direct": false,
"version": "1.1.5",
"ecosystem": "npm"
},
{
"name": "@rolldown/binding-linux-arm-gnueabihf",
"direct": false,
"version": "1.1.5",
"ecosystem": "npm"
},
{
"name": "@rolldown/binding-linux-arm64-gnu",
"direct": false,
"version": "1.1.5",
"ecosystem": "npm"
},
{
"name": "@rolldown/binding-linux-arm64-musl",
"direct": false,
"version": "1.1.5",
"ecosystem": "npm"
},
{
"name": "@rolldown/binding-linux-ppc64-gnu",
"direct": false,
"version": "1.1.5",
"ecosystem": "npm"
},
{
"name": "@rolldown/binding-linux-s390x-gnu",
"direct": false,
"version": "1.1.5",
"ecosystem": "npm"
},
{
"name": "@rolldown/binding-linux-x64-gnu",
"direct": false,
"version": "1.1.5",
"ecosystem": "npm"
},
{
"name": "@rolldown/binding-linux-x64-musl",
"direct": false,
"version": "1.1.5",
"ecosystem": "npm"
},
{
"name": "@rolldown/binding-openharmony-arm64",
"direct": false,
"version": "1.1.5",
"ecosystem": "npm"
},
{
"name": "@rolldown/binding-wasm32-wasi",
"direct": false,
"version": "1.1.5",
"ecosystem": "npm"
},
{
"name": "@rolldown/binding-win32-arm64-msvc",
"direct": false,
"version": "1.1.5",
"ecosystem": "npm"
},
{
"name": "@rolldown/binding-win32-x64-msvc",
"direct": false,
"version": "1.1.5",
"ecosystem": "npm"
},
{
"name": "@rolldown/plugin-babel",
"direct": false,
"version": "0.2.3",
"ecosystem": "npm"
},
{
"name": "@rolldown/pluginutils",
"direct": false,
"version": "1.0.1",
"ecosystem": "npm"
},
{
"name": "@sindresorhus/is",
"direct": false,
"version": "7.2.0",
"ecosystem": "npm"
},
{
"name": "@speed-highlight/core",
"direct": false,
"version": "1.2.17",
"ecosystem": "npm"
},
{
"name": "@standard-schema/spec",
"direct": false,
"version": "1.1.0",
"ecosystem": "npm"
},
{
"name": "@tybys/wasm-util",
"direct": false,
"version": "0.10.3",
"ecosystem": "npm"
},
{
"name": "@types/chai",
"direct": false,
"version": "5.2.3",
"ecosystem": "npm"
},
{
"name": "@types/deep-eql",
"direct": false,
"version": "4.0.2",
"ecosystem": "npm"
},
{
"name": "@types/estree",
"direct": false,
"version": "1.0.9",
"ecosystem": "npm"
},
{
"name": "@types/gensync",
"direct": false,
"version": "1.0.5",
"ecosystem": "npm"
},
{
"name": "@types/jsesc",
"direct": false,
"version": "2.5.1",
"ecosystem": "npm"
},
{
"name": "@types/json-schema",
"direct": false,
"version": "7.0.15",
"ecosystem": "npm"
},
{
"name": "@types/node",
"direct": false,
"version": "26.1.1",
"ecosystem": "npm"
},
{
"name": "@typescript/typescript-aix-ppc64",
"direct": false,
"version": "7.0.2",
"ecosystem": "npm"
},
{
"name": "@typescript/typescript-darwin-arm64",
"direct": false,
"version": "7.0.2",
"ecosystem": "npm"
},
{
"name": "@typescript/typescript-darwin-x64",
"direct": false,
"version": "7.0.2",
"ecosystem": "npm"
},
{
"name": "@typescript/typescript-freebsd-arm64",
"direct": false,
"version": "7.0.2",
"ecosystem": "npm"
},
{
"name": "@typescript/typescript-freebsd-x64",
"direct": false,
"version": "7.0.2",
"ecosystem": "npm"
},
{
"name": "@typescript/typescript-linux-arm",
"direct": false,
"version": "7.0.2",
"ecosystem": "npm"
},
{
"name": "@typescript/typescript-linux-arm64",
"direct": false,
"version": "7.0.2",
"ecosystem": "npm"
},
{
"name": "@typescript/typescript-linux-loong64",
"direct": false,
"version": "7.0.2",
"ecosystem": "npm"
},
{
"name": "@typescript/typescript-linux-mips64el",
"direct": false,
"version": "7.0.2",
"ecosystem": "npm"
},
{
"name": "@typescript/typescript-linux-ppc64",
"direct": false,
"version": "7.0.2",
"ecosystem": "npm"
},
{
"name": "@typescript/typescript-linux-riscv64",
"direct": false,
"version": "7.0.2",
"ecosystem": "npm"
},
{
"name": "@typescript/typescript-linux-s390x",
"direct": false,
"version": "7.0.2",
"ecosystem": "npm"
},
{
"name": "@typescript/typescript-linux-x64",
"direct": false,
"version": "7.0.2",
"ecosystem": "npm"
},
{
"name": "@typescript/typescript-netbsd-arm64",
"direct": false,
"version": "7.0.2",
"ecosystem": "npm"
},
{
"name": "@typescript/typescript-netbsd-x64",
"direct": false,
"version": "7.0.2",
"ecosystem": "npm"
},
{
"name": "@typescript/typescript-openbsd-arm64",
"direct": false,
"version": "7.0.2",
"ecosystem": "npm"
},
{
"name": "@typescript/typescript-openbsd-x64",
"direct": false,
"version": "7.0.2",
"ecosystem": "npm"
},
{
"name": "@typescript/typescript-sunos-x64",
"direct": false,
"version": "7.0.2",
"ecosystem": "npm"
},
{
"name": "@typescript/typescript-win32-arm64",
"direct": false,
"version": "7.0.2",
"ecosystem": "npm"
},
{
"name": "@typescript/typescript-win32-x64",
"direct": false,
"version": "7.0.2",
"ecosystem": "npm"
},
{
"name": "@vitest/coverage-v8",
"direct": false,
"version": "4.1.10",
"ecosystem": "npm"
},
{
"name": "@vitest/expect",
"direct": false,
"version": "4.1.10",
"ecosystem": "npm"
},
{
"name": "@vitest/mocker",
"direct": false,
"version": "4.1.10",
"ecosystem": "npm"
},
{
"name": "@vitest/pretty-format",
"direct": false,
"version": "4.1.10",
"ecosystem": "npm"
},
{
"name": "@vitest/runner",
"direct": false,
"version": "4.1.10",
"ecosystem": "npm"
},
{
"name": "@vitest/snapshot",
"direct": false,
"version": "4.1.10",
"ecosystem": "npm"
},
{
"name": "@vitest/spy",
"direct": false,
"version": "4.1.10",
"ecosystem": "npm"
},
{
"name": "@vitest/utils",
"direct": false,
"version": "4.1.10",
"ecosystem": "npm"
},
{
"name": "accepts",
"direct": false,
"version": "2.0.0",
"ecosystem": "npm"
},
{
"name": "acorn",
"direct": false,
"version": "8.17.0",
"ecosystem": "npm"
},
{
"name": "agents",
"direct": false,
"version": "0.17.4",
"ecosystem": "npm"
},
{
"name": "ajv",
"direct": false,
"version": "8.20.0",
"ecosystem": "npm"
},
{
"name": "ajv-formats",
"direct": false,
"version": "3.0.1",
"ecosystem": "npm"
},
{
"name": "ansi-regex",
"direct": false,
"version": "6.2.2",
"ecosystem": "npm"
},
{
"name": "ansi-styles",
"direct": false,
"version": "6.2.3",
"ecosystem": "npm"
},
{
"name": "assertion-error",
"direct": false,
"version": "2.0.1",
"ecosystem": "npm"
},
{
"name": "ast-v8-to-istanbul",
"direct": false,
"version": "1.0.3",
"ecosystem": "npm"
},
{
"name": "baseline-browser-mapping",
"direct": false,
"version": "2.10.43",
"ecosystem": "npm"
},
{
"name": "blake3-wasm",
"direct": false,
"version": "2.1.5",
"ecosystem": "npm"
},
{
"name": "body-parser",
"direct": false,
"version": "2.3.0",
"ecosystem": "npm"
},
{
"name": "browserslist",
"direct": false,
"version": "4.28.6",
"ecosystem": "npm"
},
{
"name": "bytes",
"direct": false,
"version": "3.1.2",
"ecosystem": "npm"
},
{
"name": "call-bind-apply-helpers",
"direct": false,
"version": "1.0.2",
"ecosystem": "npm"
},
{
"name": "call-bound",
"direct": false,
"version": "1.0.4",
"ecosystem": "npm"
},
{
"name": "caniuse-lite",
"direct": false,
"version": "1.0.30001806",
"ecosystem": "npm"
},
{
"name": "chai",
"direct": false,
"version": "6.2.2",
"ecosystem": "npm"
},
{
"name": "cjs-module-lexer",
"direct": false,
"version": "1.2.3",
"ecosystem": "npm"
},
{
"name": "cliui",
"direct": false,
"version": "9.0.1",
"ecosystem": "npm"
},
{
"name": "content-disposition",
"direct": false,
"version": "1.1.0",
"ecosystem": "npm"
},
{
"name": "content-type",
"direct": false,
"version": "1.0.5",
"ecosystem": "npm"
},
{
"name": "content-type",
"direct": false,
"version": "2.0.0",
"ecosystem": "npm"
},
{
"name": "convert-source-map",
"direct": false,
"version": "2.0.0",
"ecosystem": "npm"
},
{
"name": "cookie",
"direct": false,
"version": "0.7.2",
"ecosystem": "npm"
},
{
"name": "cookie",
"direct": false,
"version": "1.1.1",
"ecosystem": "npm"
},
{
"name": "cookie-signature",
"direct": false,
"version": "1.2.2",
"ecosystem": "npm"
},
{
"name": "core-js-pure",
"direct": false,
"version": "3.49.0",
"ecosystem": "npm"
},
{
"name": "cors",
"direct": false,
"version": "2.8.6",
"ecosystem": "npm"
},
{
"name": "cron-schedule",
"direct": false,
"version": "6.0.0",
"ecosystem": "npm"
},
{
"name": "cross-spawn",
"direct": false,
"version": "7.0.6",
"ecosystem": "npm"
},
{
"name": "debug",
"direct": false,
"version": "4.4.3",
"ecosystem": "npm"
},
{
"name": "depd",
"direct": false,
"version": "2.0.0",
"ecosystem": "npm"
},
{
"name": "detect-libc",
"direct": false,
"version": "2.1.2",
"ecosystem": "npm"
},
{
"name": "dunder-proto",
"direct": false,
"version": "1.0.1",
"ecosystem": "npm"
},
{
"name": "ee-first",
"direct": false,
"version": "1.1.1",
"ecosystem": "npm"
},
{
"name": "electron-to-chromium",
"direct": false,
"version": "1.5.393",
"ecosystem": "npm"
},
{
"name": "emoji-regex",
"direct": false,
"version": "10.6.0",
"ecosystem": "npm"
},
{
"name": "empathic",
"direct": false,
"version": "2.0.1",
"ecosystem": "npm"
},
{
"name": "encodeurl",
"direct": false,
"version": "2.0.0",
"ecosystem": "npm"
},
{
"name": "error-stack-parser-es",
"direct": false,
"version": "1.0.5",
"ecosystem": "npm"
},
{
"name": "es-define-property",
"direct": false,
"version": "1.0.1",
"ecosystem": "npm"
},
{
"name": "es-errors",
"direct": false,
"version": "1.3.0",
"ecosystem": "npm"
},
{
"name": "es-module-lexer",
"direct": false,
"version": "2.1.0",
"ecosystem": "npm"
},
{
"name": "es-object-atoms",
"direct": false,
"version": "1.1.2",
"ecosystem": "npm"
},
{
"name": "esbuild",
"direct": false,
"version": "0.28.1",
"ecosystem": "npm"
},
{
"name": "escalade",
"direct": false,
"version": "3.2.0",
"ecosystem": "npm"
},
{
"name": "escape-html",
"direct": false,
"version": "1.0.3",
"ecosystem": "npm"
},
{
"name": "estree-walker",
"direct": false,
"version": "3.0.3",
"ecosystem": "npm"
},
{
"name": "etag",
"direct": false,
"version": "1.8.1",
"ecosystem": "npm"
},
{
"name": "event-target-polyfill",
"direct": false,
"version": "0.0.4",
"ecosystem": "npm"
},
{
"name": "eventsource",
"direct": false,
"version": "3.0.7",
"ecosystem": "npm"
},
{
"name": "eventsource-parser",
"direct": false,
"version": "3.1.0",
"ecosystem": "npm"
},
{
"name": "expect-type",
"direct": false,
"version": "1.3.0",
"ecosystem": "npm"
},
{
"name": "express",
"direct": false,
"version": "5.2.1",
"ecosystem": "npm"
},
{
"name": "express-rate-limit",
"direct": false,
"version": "8.5.2",
"ecosystem": "npm"
},
{
"name": "fast-deep-equal",
"direct": false,
"version": "3.1.3",
"ecosystem": "npm"
},
{
"name": "fast-uri",
"direct": false,
"version": "3.1.4",
"ecosystem": "npm"
},
{
"name": "fdir",
"direct": false,
"version": "6.5.0",
"ecosystem": "npm"
},
{
"name": "finalhandler",
"direct": false,
"version": "2.1.1",
"ecosystem": "npm"
},
{
"name": "forwarded",
"direct": false,
"version": "0.2.0",
"ecosystem": "npm"
},
{
"name": "fresh",
"direct": false,
"version": "2.0.0",
"ecosystem": "npm"
},
{
"name": "fsevents",
"direct": false,
"version": "2.3.3",
"ecosystem": "npm"
},
{
"name": "function-bind",
"direct": false,
"version": "1.1.2",
"ecosystem": "npm"
},
{
"name": "gensync",
"direct": false,
"version": "1.0.0-beta.2",
"ecosystem": "npm"
},
{
"name": "get-caller-file",
"direct": false,
"version": "2.0.5",
"ecosystem": "npm"
},
{
"name": "get-east-asian-width",
"direct": false,
"version": "1.6.0",
"ecosystem": "npm"
},
{
"name": "get-intrinsic",
"direct": false,
"version": "1.3.0",
"ecosystem": "npm"
},
{
"name": "get-proto",
"direct": false,
"version": "1.0.1",
"ecosystem": "npm"
},
{
"name": "gopd",
"direct": false,
"version": "1.2.0",
"ecosystem": "npm"
},
{
"name": "has-flag",
"direct": false,
"version": "4.0.0",
"ecosystem": "npm"
},
{
"name": "has-symbols",
"direct": false,
"version": "1.1.0",
"ecosystem": "npm"
},
{
"name": "hasown",
"direct": false,
"version": "2.0.4",
"ecosystem": "npm"
},
{
"name": "hono",
"direct": false,
"version": "4.12.31",
"ecosystem": "npm"
},
{
"name": "html-escaper",
"direct": false,
"version": "2.0.2",
"ecosystem": "npm"
},
{
"name": "http-errors",
"direct": false,
"version": "2.0.1",
"ecosystem": "npm"
},
{
"name": "iconv-lite",
"direct": false,
"version": "0.7.2",
"ecosystem": "npm"
},
{
"name": "import-meta-resolve",
"direct": false,
"version": "4.2.0",
"ecosystem": "npm"
},
{
"name": "inherits",
"direct": false,
"version": "2.0.4",
"ecosystem": "npm"
},
{
"name": "ip-address",
"direct": false,
"version": "10.2.0",
"ecosystem": "npm"
},
{
"name": "ipaddr.js",
"direct": false,
"version": "1.9.1",
"ecosystem": "npm"
},
{
"name": "is-promise",
"direct": false,
"version": "4.0.0",
"ecosystem": "npm"
},
{
"name": "isexe",
"direct": false,
"version": "2.0.0",
"ecosystem": "npm"
},
{
"name": "istanbul-lib-coverage",
"direct": false,
"version": "3.2.2",
"ecosystem": "npm"
},
{
"name": "istanbul-lib-report",
"direct": false,
"version": "3.0.1",
"ecosystem": "npm"
},
{
"name": "istanbul-reports",
"direct": false,
"version": "3.2.0",
"ecosystem": "npm"
},
{
"name": "jose",
"direct": false,
"version": "6.2.3",
"ecosystem": "npm"
},
{
"name": "js-base64",
"direct": false,
"version": "3.9.1",
"ecosystem": "npm"
},
{
"name": "js-tokens",
"direct": false,
"version": "10.0.0",
"ecosystem": "npm"
},
{
"name": "jsesc",
"direct": false,
"version": "3.1.0",
"ecosystem": "npm"
},
{
"name": "json-schema-traverse",
"direct": false,
"version": "1.0.0",
"ecosystem": "npm"
},
{
"name": "json-schema-typed",
"direct": false,
"version": "8.0.2",
"ecosystem": "npm"
},
{
"name": "json5",
"direct": false,
"version": "2.2.3",
"ecosystem": "npm"
},
{
"name": "kleur",
"direct": false,
"version": "4.1.5",
"ecosystem": "npm"
},
{
"name": "lightningcss",
"direct": false,
"version": "1.32.0",
"ecosystem": "npm"
},
{
"name": "lightningcss-android-arm64",
"direct": false,
"version": "1.32.0",
"ecosystem": "npm"
},
{
"name": "lightningcss-darwin-arm64",
"direct": false,
"version": "1.32.0",
"ecosystem": "npm"
},
{
"name": "lightningcss-darwin-x64",
"direct": false,
"version": "1.32.0",
"ecosystem": "npm"
},
{
"name": "lightningcss-freebsd-x64",
"direct": false,
"version": "1.32.0",
"ecosystem": "npm"
},
{
"name": "lightningcss-linux-arm-gnueabihf",
"direct": false,
"version": "1.32.0",
"ecosystem": "npm"
},
{
"name": "lightningcss-linux-arm64-gnu",
"direct": false,
"version": "1.32.0",
"ecosystem": "npm"
},
{
"name": "lightningcss-linux-arm64-musl",
"direct": false,
"version": "1.32.0",
"ecosystem": "npm"
},
{
"name": "lightningcss-linux-x64-gnu",
"direct": false,
"version": "1.32.0",
"ecosystem": "npm"
},
{
"name": "lightningcss-linux-x64-musl",
"direct": false,
"version": "1.32.0",
"ecosystem": "npm"
},
{
"name": "lightningcss-win32-arm64-msvc",
"direct": false,
"version": "1.32.0",
"ecosystem": "npm"
},
{
"name": "lightningcss-win32-x64-msvc",
"direct": false,
"version": "1.32.0",
"ecosystem": "npm"
},
{
"name": "lru-cache",
"direct": false,
"version": "11.5.2",
"ecosystem": "npm"
},
{
"name": "magic-string",
"direct": false,
"version": "0.30.21",
"ecosystem": "npm"
},
{
"name": "magicast",
"direct": false,
"version": "0.5.3",
"ecosystem": "npm"
},
{
"name": "make-dir",
"direct": false,
"version": "4.0.0",
"ecosystem": "npm"
},
{
"name": "math-intrinsics",
"direct": false,
"version": "1.1.0",
"ecosystem": "npm"
},
{
"name": "media-typer",
"direct": false,
"version": "1.1.0",
"ecosystem": "npm"
},
{
"name": "merge-descriptors",
"direct": false,
"version": "2.0.0",
"ecosystem": "npm"
},
{
"name": "mime-db",
"direct": false,
"version": "1.52.0",
"ecosystem": "npm"
},
{
"name": "mime-db",
"direct": false,
"version": "1.54.0",
"ecosystem": "npm"
},
{
"name": "mime-types",
"direct": false,
"version": "2.1.35",
"ecosystem": "npm"
},
{
"name": "mime-types",
"direct": false,
"version": "3.0.2",
"ecosystem": "npm"
},
{
"name": "mimetext",
"direct": false,
"version": "3.0.28",
"ecosystem": "npm"
},
{
"name": "miniflare",
"direct": false,
"version": "4.20260722.0",
"ecosystem": "npm"
},
{
"name": "ms",
"direct": false,
"version": "2.1.3",
"ecosystem": "npm"
},
{
"name": "nanoid",
"direct": false,
"version": "3.3.16",
"ecosystem": "npm"
},
{
"name": "nanoid",
"direct": false,
"version": "5.1.16",
"ecosystem": "npm"
},
{
"name": "negotiator",
"direct": false,
"version": "1.0.0",
"ecosystem": "npm"
},
{
"name": "node-releases",
"direct": false,
"version": "2.0.51",
"ecosystem": "npm"
},
{
"name": "object-assign",
"direct": false,
"version": "4.1.1",
"ecosystem": "npm"
},
{
"name": "object-inspect",
"direct": false,
"version": "1.13.4",
"ecosystem": "npm"
},
{
"name": "obug",
"direct": false,
"version": "2.1.2",
"ecosystem": "npm"
},
{
"name": "on-finished",
"direct": false,
"version": "2.4.1",
"ecosystem": "npm"
},
{
"name": "once",
"direct": false,
"version": "1.4.0",
"ecosystem": "npm"
},
{
"name": "parseurl",
"direct": false,
"version": "1.3.3",
"ecosystem": "npm"
},
{
"name": "partyserver",
"direct": false,
"version": "0.5.8",
"ecosystem": "npm"
},
{
"name": "partysocket",
"direct": false,
"version": "1.3.0",
"ecosystem": "npm"
},
{
"name": "path-key",
"direct": false,
"version": "3.1.1",
"ecosystem": "npm"
},
{
"name": "path-to-regexp",
"direct": false,
"version": "6.3.0",
"ecosystem": "npm"
},
{
"name": "path-to-regexp",
"direct": false,
"version": "8.4.2",
"ecosystem": "npm"
},
{
"name": "pathe",
"direct": false,
"version": "2.0.3",
"ecosystem": "npm"
},
{
"name": "picocolors",
"direct": false,
"version": "1.1.1",
"ecosystem": "npm"
},
{
"name": "picomatch",
"direct": false,
"version": "4.0.5",
"ecosystem": "npm"
},
{
"name": "pkce-challenge",
"direct": false,
"version": "5.0.1",
"ecosystem": "npm"
},
{
"name": "postcss",
"direct": false,
"version": "8.5.23",
"ecosystem": "npm"
},
{
"name": "proxy-addr",
"direct": false,
"version": "2.0.7",
"ecosystem": "npm"
},
{
"name": "qs",
"direct": false,
"version": "6.15.2",
"ecosystem": "npm"
},
{
"name": "range-parser",
"direct": false,
"version": "1.2.1",
"ecosystem": "npm"
},
{
"name": "raw-body",
"direct": false,
"version": "3.0.2",
"ecosystem": "npm"
},
{
"name": "react",
"direct": false,
"version": "19.2.7",
"ecosystem": "npm"
},
{
"name": "require-from-string",
"direct": false,
"version": "2.0.2",
"ecosystem": "npm"
},
{
"name": "rolldown",
"direct": false,
"version": "1.1.5",
"ecosystem": "npm"
},
{
"name": "router",
"direct": false,
"version": "2.2.0",
"ecosystem": "npm"
},
{
"name": "safer-buffer",
"direct": false,
"version": "2.1.2",
"ecosystem": "npm"
},
{
"name": "semver",
"direct": false,
"version": "7.8.5",
"ecosystem": "npm"
},
{
"name": "send",
"direct": false,
"version": "1.2.1",
"ecosystem": "npm"
},
{
"name": "serve-static",
"direct": false,
"version": "2.2.1",
"ecosystem": "npm"
},
{
"name": "setprototypeof",
"direct": false,
"version": "1.2.0",
"ecosystem": "npm"
},
{
"name": "sharp",
"direct": false,
"version": "0.35.2",
"ecosystem": "npm"
},
{
"name": "shebang-command",
"direct": false,
"version": "2.0.0",
"ecosystem": "npm"
},
{
"name": "shebang-regex",
"direct": false,
"version": "3.0.0",
"ecosystem": "npm"
},
{
"name": "side-channel",
"direct": false,
"version": "1.1.0",
"ecosystem": "npm"
},
{
"name": "side-channel-list",
"direct": false,
"version": "1.0.1",
"ecosystem": "npm"
},
{
"name": "side-channel-map",
"direct": false,
"version": "1.0.1",
"ecosystem": "npm"
},
{
"name": "side-channel-weakmap",
"direct": false,
"version": "1.0.2",
"ecosystem": "npm"
},
{
"name": "siginfo",
"direct": false,
"version": "2.0.0",
"ecosystem": "npm"
},
{
"name": "source-map-js",
"direct": false,
"version": "1.2.1",
"ecosystem": "npm"
},
{
"name": "stackback",
"direct": false,
"version": "0.0.2",
"ecosystem": "npm"
},
{
"name": "statuses",
"direct": false,
"version": "2.0.2",
"ecosystem": "npm"
},
{
"name": "std-env",
"direct": false,
"version": "4.1.0",
"ecosystem": "npm"
},
{
"name": "string-width",
"direct": false,
"version": "7.2.0",
"ecosystem": "npm"
},
{
"name": "strip-ansi",
"direct": false,
"version": "7.2.0",
"ecosystem": "npm"
},
{
"name": "supports-color",
"direct": false,
"version": "10.2.2",
"ecosystem": "npm"
},
{
"name": "supports-color",
"direct": false,
"version": "7.2.0",
"ecosystem": "npm"
},
{
"name": "tinybench",
"direct": false,
"version": "2.9.0",
"ecosystem": "npm"
},
{
"name": "tinyexec",
"direct": false,
"version": "1.2.4",
"ecosystem": "npm"
},
{
"name": "tinyglobby",
"direct": false,
"version": "0.2.17",
"ecosystem": "npm"
},
{
"name": "tinyrainbow",
"direct": false,
"version": "3.1.0",
"ecosystem": "npm"
},
{
"name": "toidentifier",
"direct": false,
"version": "1.0.1",
"ecosystem": "npm"
},
{
"name": "tslib",
"direct": false,
"version": "2.8.1",
"ecosystem": "npm"
},
{
"name": "type-is",
"direct": false,
"version": "2.1.0",
"ecosystem": "npm"
},
{
"name": "typescript",
"direct": false,
"version": "7.0.2",
"ecosystem": "npm"
},
{
"name": "undici",
"direct": false,
"version": "7.28.0",
"ecosystem": "npm"
},
{
"name": "undici-types",
"direct": false,
"version": "8.3.0",
"ecosystem": "npm"
},
{
"name": "unenv",
"direct": false,
"version": "2.0.0-rc.24",
"ecosystem": "npm"
},
{
"name": "unpipe",
"direct": false,
"version": "1.0.0",
"ecosystem": "npm"
},
{
"name": "update-browserslist-db",
"direct": false,
"version": "1.2.3",
"ecosystem": "npm"
},
{
"name": "vary",
"direct": false,
"version": "1.1.2",
"ecosystem": "npm"
},
{
"name": "vite",
"direct": false,
"version": "8.1.4",
"ecosystem": "npm"
},
{
"name": "vitest",
"direct": false,
"version": "4.1.10",
"ecosystem": "npm"
},
{
"name": "which",
"direct": false,
"version": "2.0.2",
"ecosystem": "npm"
},
{
"name": "why-is-node-running",
"direct": false,
"version": "2.3.0",
"ecosystem": "npm"
},
{
"name": "workerd",
"direct": false,
"version": "1.20260722.1",
"ecosystem": "npm"
},
{
"name": "wrangler",
"direct": false,
"version": "4.114.0",
"ecosystem": "npm"
},
{
"name": "wrap-ansi",
"direct": false,
"version": "9.0.2",
"ecosystem": "npm"
},
{
"name": "wrappy",
"direct": false,
"version": "1.0.2",
"ecosystem": "npm"
},
{
"name": "ws",
"direct": false,
"version": "8.21.0",
"ecosystem": "npm"
},
{
"name": "y18n",
"direct": false,
"version": "5.0.8",
"ecosystem": "npm"
},
{
"name": "yaml",
"direct": false,
"version": "2.9.0",
"ecosystem": "npm"
},
{
"name": "yargs",
"direct": false,
"version": "18.0.0",
"ecosystem": "npm"
},
{
"name": "yargs-parser",
"direct": false,
"version": "22.0.0",
"ecosystem": "npm"
},
{
"name": "youch",
"direct": false,
"version": "4.1.0-beta.10",
"ecosystem": "npm"
},
{
"name": "youch-core",
"direct": false,
"version": "0.3.3",
"ecosystem": "npm"
},
{
"name": "zod-to-json-schema",
"direct": false,
"version": "3.25.2",
"ecosystem": "npm"
}
],
"collected": true,
"truncated": false,
"total_count": 372,
"direct_count": 5,
"indirect_count": 367
}
},
"maintainership": {
"issues": {
"open_prs": 0,
"merged_prs": 86,
"open_issues": 2,
"closed_ratio": 0.846,
"closed_issues": 11,
"closed_unmerged_prs": 2
},
"bus_factor": 1,
"bot_contributors": 1,
"top_contributors": [
{
"type": "User",
"login": "chrischall",
"commits": 67,
"avatar_url": "https://avatars.githubusercontent.com/u/10564245?v=4"
}
],
"contributors_sampled": 1,
"top_contributor_share": 1
},
"quality_signals": {
"has_ci": true,
"has_tests": true,
"ci_workflows": [
"auto-merge.yml",
"ci.yml",
"claude.yml",
"deploy-connector.yml",
"pr-auto-review.yml",
"release-please.yml"
],
"has_docs_dir": true,
"linter_configs": [],
"has_editorconfig": false,
"has_linter_config": false,
"has_precommit_config": false
},
"security_signals": {
"lockfiles": [
"package-lock.json"
],
"scorecard": {
"checks": [
{
"name": "Binary-Artifacts",
"score": 10,
"reason": "no binaries found in the repo",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#binary-artifacts"
},
{
"name": "Branch-Protection",
"score": 3,
"reason": "branch protection is not maximal on development and all release branches",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#branch-protection"
},
{
"name": "CI-Tests",
"score": 10,
"reason": "30 out of 30 merged PRs checked by a CI test -- score normalized to 10",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#ci-tests"
},
{
"name": "CII-Best-Practices",
"score": 0,
"reason": "no effort to earn an OpenSSF best practices badge detected",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#cii-best-practices"
},
{
"name": "Code-Review",
"score": 0,
"reason": "Found 0/22 approved changesets -- score normalized to 0",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#code-review"
},
{
"name": "Contributors",
"score": 0,
"reason": "project has 0 contributing companies or organizations -- score normalized to 0",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#contributors"
},
{
"name": "Dangerous-Workflow",
"score": 10,
"reason": "no dangerous workflow patterns detected",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#dangerous-workflow"
},
{
"name": "Dependency-Update-Tool",
"score": 10,
"reason": "update tool detected",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#dependency-update-tool"
},
{
"name": "Fuzzing",
"score": 0,
"reason": "project is not fuzzed",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#fuzzing"
},
{
"name": "License",
"score": 10,
"reason": "license file detected",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#license"
},
{
"name": "Maintained",
"score": 0,
"reason": "project was created within the last 90 days. Please review its contents carefully",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#maintained"
},
{
"name": "Packaging",
"score": null,
"reason": "packaging workflow not detected",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#packaging"
},
{
"name": "Pinned-Dependencies",
"score": 0,
"reason": "dependency not pinned by hash detected -- score normalized to 0",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#pinned-dependencies"
},
{
"name": "SAST",
"score": 0,
"reason": "SAST tool is not run on all commits -- score normalized to 0",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#sast"
},
{
"name": "Security-Policy",
"score": 0,
"reason": "security policy file not detected",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#security-policy"
},
{
"name": "Signed-Releases",
"score": 0,
"reason": "Project has not signed or included provenance with any releases.",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#signed-releases"
},
{
"name": "Token-Permissions",
"score": 0,
"reason": "detected GitHub workflow tokens with excessive permissions",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#token-permissions"
},
{
"name": "Vulnerabilities",
"score": 9,
"reason": "1 existing vulnerabilities detected",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#vulnerabilities"
}
],
"commit": "e574b2ce7cd47d7dfc0ac14132e44aaeae0e332f",
"ran_at": "2026-07-25T15:23:16Z",
"aggregate_score": 3.9,
"scorecard_version": "v5.5.0"
},
"has_codeql_workflow": false,
"has_security_policy": false,
"has_dependabot_config": true
},
"contribution_flow": {
"collected": true,
"ci_last_run_at": "2026-07-25T04:25:48Z",
"oldest_open_prs": [],
"last_merged_pr_at": "2026-07-25T04:25:36Z",
"ci_last_conclusion": "SUCCESS",
"oldest_open_issues": [
{
"number": 13,
"created_at": "2026-06-08T14:42:27Z",
"last_comment_at": null,
"last_comment_author": null
},
{
"number": 92,
"created_at": "2026-07-19T15:09:49Z",
"last_comment_at": null,
"last_comment_author": null
}
]
}
},
"config": {
"disabled_metrics": [],
"disabled_categories": [],
"disabled_components": {}
},
"source": {
"url": "https://github.com/chrischall/gemini-mcp",
"host": "github.com",
"name": "gemini-mcp",
"owner": "chrischall"
},
"metrics": {
"overall": {
"key": "overall",
"band": "moderate",
"name": "Overall health",
"note": null,
"notes": [],
"value": 57,
"inputs": {
"security": 49,
"vitality": 71,
"community": 32,
"governance": 56,
"engineering": 71
},
"components": []
},
"categories": [
{
"key": "vitality",
"band": "good",
"name": "Vitality",
"value": 71,
"weight": 0.22,
"metrics": [
{
"key": "development_activity",
"band": "moderate",
"name": "Development activity",
"note": null,
"notes": [],
"value": 58,
"inputs": {
"commits_last_year": 85,
"human_commit_share": 0.779,
"days_since_last_push": 0,
"active_weeks_last_year": 7
},
"components": [
{
"key": "push_recency",
"name": "Push recency",
"detail": "last push 0 days ago",
"points": 36,
"status": "met",
"details": [
{
"code": "push_recency",
"params": {
"days": 0
}
}
],
"max_points": 36
},
{
"key": "commit_cadence",
"name": "Commit cadence",
"detail": "7/52 weeks with commits",
"points": 4.8,
"status": "partial",
"details": [
{
"code": "commit_cadence_weeks",
"params": {
"weeks": 7
}
}
],
"max_points": 36
},
{
"key": "commit_volume",
"name": "Commit volume",
"detail": "85 commits in the last year",
"points": 17.4,
"status": "partial",
"details": [
{
"code": "commits_last_year",
"params": {
"count": 85
}
}
],
"max_points": 18
},
{
"key": "openssf_scorecard_maintained",
"name": "OpenSSF Scorecard: Maintained",
"detail": "project was created within the last 90 days. Please review its contents carefully",
"points": 0,
"status": "missed",
"details": [],
"max_points": 10
}
]
},
{
"key": "release_discipline",
"band": "excellent",
"name": "Release discipline",
"note": null,
"notes": [],
"value": 90,
"inputs": {
"releases_count": 15,
"latest_release_tag": "v1.0.3",
"releases_from_tags": false,
"days_since_latest_release": 5,
"mean_days_between_releases": 1.5
},
"components": [
{
"key": "ships_releases",
"name": "Ships releases",
"detail": "15 releases published",
"points": 27,
"status": "met",
"details": [
{
"code": "releases_published",
"params": {
"count": 15
}
}
],
"max_points": 27
},
{
"key": "release_recency",
"name": "Release recency",
"detail": "latest release 5 days ago",
"points": 36,
"status": "met",
"details": [
{
"code": "release_recency",
"params": {
"days": 5
}
}
],
"max_points": 36
},
{
"key": "release_cadence",
"name": "Release cadence",
"detail": "a release every ~1.5 days",
"points": 27,
"status": "met",
"details": [
{
"code": "release_cadence",
"params": {
"gap": 1.5
}
}
],
"max_points": 27
},
{
"key": "openssf_scorecard_signed_releases",
"name": "OpenSSF Scorecard: Signed-Releases",
"detail": "Project has not signed or included provenance with any releases.",
"points": 0,
"status": "missed",
"details": [],
"max_points": 10
}
]
},
{
"key": "abandonment",
"band": "excellent",
"name": "Abandonment",
"note": null,
"notes": [],
"value": 100,
"inputs": {
"cap": null,
"state": "unverified",
"guards": [],
"signals": [],
"red_flag": false,
"multiplier_pct": 100,
"declared_reason": null,
"unverified_reason": "repository_too_young",
"unanswered_open_prs": null,
"unanswered_open_issues": null,
"days_since_last_merged_pr": null,
"days_since_last_human_commit": null,
"days_since_last_human_commit_is_floor": false
},
"components": [
{
"key": "project_is_still_maintained",
"name": "Project is still maintained",
"detail": "maintenance record not established from the collected data",
"points": 100,
"status": "met",
"details": [
{
"code": "abandonment_unverified",
"params": {}
}
],
"max_points": 100
}
]
}
],
"description": "Is the project alive — is code being written and are releases shipping?"
},
{
"key": "community",
"band": "at_risk",
"name": "Community & Adoption",
"value": 32,
"weight": 0.18,
"metrics": [
{
"key": "popularity",
"band": "critical",
"name": "Popularity & adoption",
"note": null,
"notes": [],
"value": 1,
"inputs": {
"forks": 0,
"stars": 0,
"watchers": 0,
"growth_state": "unverified",
"growth_factor_pct": 100,
"growth_unverified_reason": "no_history"
},
"components": [
{
"key": "stars",
"name": "Stars",
"detail": "0 stars",
"points": 0,
"status": "missed",
"details": [
{
"code": "stars",
"params": {
"count": 0
}
}
],
"max_points": 60
},
{
"key": "forks",
"name": "Forks",
"detail": "0 forks",
"points": 0,
"status": "missed",
"details": [
{
"code": "forks",
"params": {
"count": 0
}
}
],
"max_points": 25
},
{
"key": "watchers",
"name": "Watchers",
"detail": "0 watchers",
"points": 0,
"status": "missed",
"details": [
{
"code": "watchers",
"params": {
"count": 0
}
}
],
"max_points": 15
}
]
},
{
"key": "community_health",
"band": "moderate",
"name": "Community health",
"note": null,
"notes": [],
"value": 50,
"inputs": {
"has_readme": true,
"has_license": true,
"has_contributing": false,
"has_issue_template": false,
"has_code_of_conduct": false,
"has_pull_request_template": false
},
"components": [
{
"key": "readme",
"name": "README",
"detail": null,
"points": 22.5,
"status": "met",
"details": [],
"max_points": 22.5
},
{
"key": "license",
"name": "License",
"detail": "recognized license (MIT)",
"points": 22.5,
"status": "met",
"details": [
{
"code": "license_standard",
"params": {}
},
{
"code": "license_spdx",
"params": {
"spdx": "MIT"
}
}
],
"max_points": 22.5
},
{
"key": "contributing_guide",
"name": "CONTRIBUTING guide",
"detail": null,
"points": 0,
"status": "missed",
"details": [],
"max_points": 18
},
{
"key": "code_of_conduct",
"name": "Code of conduct",
"detail": null,
"points": 0,
"status": "missed",
"details": [],
"max_points": 13.5
},
{
"key": "issue_template",
"name": "Issue template",
"detail": null,
"points": 0,
"status": "missed",
"details": [],
"max_points": 7.2
},
{
"key": "pr_template",
"name": "PR template",
"detail": null,
"points": 0,
"status": "missed",
"details": [],
"max_points": 6.3
}
]
},
{
"key": "ecosystem_adoption",
"band": "moderate",
"name": "Ecosystem adoption (downloads)",
"note": "Excluded from scoring (no data or not applicable): Registry dependents. Remaining weights renormalized.",
"notes": [
{
"code": "excluded_no_data",
"params": {
"components": [
"registry_dependents"
]
}
},
{
"code": "weights_renormalized",
"params": {}
}
],
"value": 56,
"inputs": {
"packages": [
"@chrischall/gemini-mcp"
],
"dependents": null,
"ecosystems": "npm",
"total_downloads": null,
"monthly_downloads": 2389
},
"components": [
{
"key": "monthly_downloads",
"name": "Monthly downloads",
"detail": "2,389 downloads/month across npm",
"points": 45,
"status": "partial",
"details": [
{
"code": "downloads_monthly",
"params": {
"count": 2389,
"ecosystems": "npm"
}
}
],
"max_points": 80
},
{
"key": "registry_dependents",
"name": "Registry dependents",
"detail": "not reported by this ecosystem",
"points": 0,
"status": "excluded",
"details": [
{
"code": "not_reported_by_this_ecosystem",
"params": {}
}
],
"max_points": 20
}
]
}
],
"description": "Does the project have users, downloads, attention, and a welcoming setup for contributors?"
},
{
"key": "governance",
"band": "moderate",
"name": "Sustainability & Governance",
"value": 56,
"weight": 0.24,
"metrics": [
{
"key": "maintainer_resilience",
"band": "critical",
"name": "Maintainer resilience (bus factor)",
"note": null,
"notes": [],
"value": 10,
"inputs": {
"bus_factor": 1,
"contributors_sampled": 1,
"top_contributor_share": 1
},
"components": [
{
"key": "bus_factor",
"name": "Bus factor",
"detail": "1 contributor(s) cover half of all commits",
"points": 9,
"status": "partial",
"details": [
{
"code": "bus_factor",
"params": {
"count": 1
}
}
],
"max_points": 54
},
{
"key": "commit_distribution",
"name": "Commit distribution",
"detail": "top contributor authored 100% of commits",
"points": 0,
"status": "missed",
"details": [
{
"code": "top_contributor_share",
"params": {
"share": 100
}
}
],
"max_points": 22.5
},
{
"key": "contributor_breadth",
"name": "Contributor breadth",
"detail": "1 contributors",
"points": 1.4,
"status": "partial",
"details": [
{
"code": "contributors_sampled",
"params": {
"count": 1
}
}
],
"max_points": 13.5
},
{
"key": "openssf_scorecard_contributors",
"name": "OpenSSF Scorecard: Contributors",
"detail": "project has 0 contributing companies or organizations -- score normalized to 0",
"points": 0,
"status": "missed",
"details": [],
"max_points": 10
}
]
},
{
"key": "responsiveness",
"band": "good",
"name": "Issue & PR responsiveness",
"note": null,
"notes": [],
"value": 77,
"inputs": {
"merged_prs": 86,
"open_issues": 2,
"closed_issues": 11,
"issue_closed_ratio": 0.846,
"closed_unmerged_prs": 2
},
"components": [
{
"key": "issue_resolution",
"name": "Issue resolution",
"detail": "85% of issues closed",
"points": 39.6,
"status": "partial",
"details": [
{
"code": "issues_closed_share",
"params": {
"share": 85
}
}
],
"max_points": 46.75
},
{
"key": "pr_acceptance",
"name": "PR acceptance",
"detail": "86/88 decided PRs merged",
"points": 37.4,
"status": "partial",
"details": [
{
"code": "decided_prs_merged",
"params": {
"merged": 86,
"decided": 88
}
}
],
"max_points": 38.25
},
{
"key": "openssf_scorecard_code_review",
"name": "OpenSSF Scorecard: Code-Review",
"detail": "Found 0/22 approved changesets -- score normalized to 0",
"points": 0,
"status": "missed",
"details": [],
"max_points": 15
}
]
},
{
"key": "stewardship",
"band": "moderate",
"name": "Ownership & stewardship",
"note": "Excluded from scoring (no data or not applicable): Verified domain. Remaining weights renormalized.",
"notes": [
{
"code": "excluded_no_data",
"params": {
"components": [
"verified_domain"
]
}
},
{
"code": "weights_renormalized",
"params": {}
}
],
"value": 53,
"inputs": {
"followers": 10,
"owner_type": "User",
"is_verified": null,
"owner_login": "chrischall",
"public_repos": 64,
"account_age_days": 4207
},
"components": [
{
"key": "ownership_backing",
"name": "Ownership backing",
"detail": "personal (user) account",
"points": 10,
"status": "partial",
"details": [
{
"code": "owner_personal",
"params": {}
}
],
"max_points": 30
},
{
"key": "verified_domain",
"name": "Verified domain",
"detail": "not applicable to user accounts",
"points": 0,
"status": "excluded",
"details": [
{
"code": "not_applicable_to_user_accounts",
"params": {}
}
],
"max_points": 20
},
{
"key": "owner_reach",
"name": "Owner reach",
"detail": "10 followers of chrischall",
"points": 7.5,
"status": "partial",
"details": [
{
"code": "owner_followers",
"params": {
"count": 10,
"login": "chrischall"
}
}
],
"max_points": 25
},
{
"key": "track_record",
"name": "Track record",
"detail": "64 public repos, account ~11 yr old",
"points": 25,
"status": "met",
"details": [
{
"code": "public_repos",
"params": {
"count": 64
}
},
{
"code": "account_age_years",
"params": {
"years": 11
}
}
],
"max_points": 25
}
]
},
{
"key": "package_maintenance",
"band": "excellent",
"name": "Package maintenance",
"note": null,
"notes": [],
"value": 100,
"inputs": {
"packages": [
"@chrischall/gemini-mcp"
],
"ecosystems": "npm",
"any_deprecated": false,
"min_days_since_publish": 5
},
"components": [
{
"key": "published_resolvable",
"name": "Published & resolvable",
"detail": "1 package(s) on npm",
"points": 25,
"status": "met",
"details": [
{
"code": "packages_published",
"params": {
"count": 1,
"ecosystems": "npm"
}
}
],
"max_points": 25
},
{
"key": "publish_recency",
"name": "Publish recency",
"detail": "latest publish 5 days ago",
"points": 35,
"status": "met",
"details": [
{
"code": "publish_recency",
"params": {
"days": 5
}
}
],
"max_points": 35
},
{
"key": "version_history",
"name": "Version history",
"detail": "16 published versions",
"points": 20,
"status": "met",
"details": [
{
"code": "published_versions",
"params": {
"count": 16
}
}
],
"max_points": 20
},
{
"key": "not_deprecated",
"name": "Not deprecated",
"detail": "active, not deprecated or yanked",
"points": 20,
"status": "met",
"details": [
{
"code": "package_not_deprecated",
"params": {}
}
],
"max_points": 20
}
]
}
],
"description": "Will the project survive its people — bus factor, responsiveness, who backs it, and package upkeep?"
},
{
"key": "engineering",
"band": "good",
"name": "Engineering Quality",
"value": 71,
"weight": 0.2,
"metrics": [
{
"key": "engineering_practices",
"band": "moderate",
"name": "Engineering practices",
"note": null,
"notes": [],
"value": 68,
"inputs": {
"has_ci": true,
"has_tests": true,
"has_editorconfig": false,
"has_linter_config": false,
"has_precommit_config": false
},
"components": [
{
"key": "ci_workflows",
"name": "CI workflows",
"detail": "6 workflow(s)",
"points": 24,
"status": "met",
"details": [
{
"code": "ci_workflows",
"params": {
"count": 6
}
}
],
"max_points": 24
},
{
"key": "tests_present",
"name": "Tests present",
"detail": null,
"points": 24,
"status": "met",
"details": [],
"max_points": 24
},
{
"key": "linter_config",
"name": "Linter config",
"detail": null,
"points": 0,
"status": "missed",
"details": [],
"max_points": 16
},
{
"key": "pre_commit_hooks",
"name": "Pre-commit hooks",
"detail": null,
"points": 0,
"status": "missed",
"details": [],
"max_points": 9.6
},
{
"key": "editorconfig",
"name": ".editorconfig",
"detail": null,
"points": 0,
"status": "missed",
"details": [],
"max_points": 6.4
},
{
"key": "openssf_scorecard_ci_tests",
"name": "OpenSSF Scorecard: CI-Tests",
"detail": "30 out of 30 merged PRs checked by a CI test -- score normalized to 10",
"points": 20,
"status": "met",
"details": [],
"max_points": 20
}
]
},
{
"key": "documentation",
"band": "good",
"name": "Documentation",
"note": null,
"notes": [],
"value": 75,
"inputs": {
"topics": [],
"has_wiki": true,
"homepage": null,
"has_readme": true,
"has_docs_dir": true,
"has_description": true
},
"components": [
{
"key": "readme",
"name": "README",
"detail": null,
"points": 30,
"status": "met",
"details": [],
"max_points": 30
},
{
"key": "documentation_directory",
"name": "Documentation directory",
"detail": null,
"points": 25,
"status": "met",
"details": [],
"max_points": 25
},
{
"key": "documentation_homepage_site",
"name": "Documentation / homepage site",
"detail": null,
"points": 0,
"status": "missed",
"details": [],
"max_points": 15
},
{
"key": "repository_description",
"name": "Repository description",
"detail": null,
"points": 10,
"status": "met",
"details": [],
"max_points": 10
},
{
"key": "topics",
"name": "Topics",
"detail": null,
"points": 0,
"status": "missed",
"details": [],
"max_points": 10
},
{
"key": "wiki",
"name": "Wiki",
"detail": null,
"points": 10,
"status": "met",
"details": [],
"max_points": 10
}
]
}
],
"description": "Are baseline engineering and documentation practices in place?"
},
{
"key": "security",
"band": "at_risk",
"name": "Security",
"value": 49,
"weight": 0.16,
"metrics": [
{
"key": "security_posture",
"band": "at_risk",
"name": "Security posture",
"note": "Excluded from scoring (no data or not applicable): Packaging. Remaining weights renormalized.",
"notes": [
{
"code": "excluded_no_data",
"params": {
"components": [
"packaging"
]
}
},
{
"code": "weights_renormalized",
"params": {}
}
],
"value": 39,
"inputs": {
"source": "openssf_scorecard",
"checks_evaluated": 17,
"scorecard_version": "v5.5.0",
"checks_inconclusive": 1,
"scorecard_aggregate": 3.9
},
"components": [
{
"key": "binary_artifacts",
"name": "Binary-Artifacts",
"detail": "no binaries found in the repo",
"points": 7.5,
"status": "met",
"details": [],
"max_points": 7.5
},
{
"key": "branch_protection",
"name": "Branch-Protection",
"detail": "branch protection is not maximal on development and all release branches",
"points": 2.2,
"status": "partial",
"details": [],
"max_points": 7.5
},
{
"key": "ci_tests",
"name": "CI-Tests",
"detail": "30 out of 30 merged PRs checked by a CI test -- score normalized to 10",
"points": 2.5,
"status": "met",
"details": [],
"max_points": 2.5
},
{
"key": "cii_best_practices",
"name": "CII-Best-Practices",
"detail": "no effort to earn an OpenSSF best practices badge detected",
"points": 0,
"status": "missed",
"details": [],
"max_points": 2.5
},
{
"key": "code_review",
"name": "Code-Review",
"detail": "Found 0/22 approved changesets -- score normalized to 0",
"points": 0,
"status": "missed",
"details": [],
"max_points": 7.5
},
{
"key": "contributors",
"name": "Contributors",
"detail": "project has 0 contributing companies or organizations -- score normalized to 0",
"points": 0,
"status": "missed",
"details": [],
"max_points": 2.5
},
{
"key": "dangerous_workflow",
"name": "Dangerous-Workflow",
"detail": "no dangerous workflow patterns detected",
"points": 10,
"status": "met",
"details": [],
"max_points": 10
},
{
"key": "dependency_update_tool",
"name": "Dependency-Update-Tool",
"detail": "update tool detected",
"points": 7.5,
"status": "met",
"details": [],
"max_points": 7.5
},
{
"key": "fuzzing",
"name": "Fuzzing",
"detail": "project is not fuzzed",
"points": 0,
"status": "missed",
"details": [],
"max_points": 5
},
{
"key": "license",
"name": "License",
"detail": "license file detected",
"points": 2.5,
"status": "met",
"details": [],
"max_points": 2.5
},
{
"key": "maintained",
"name": "Maintained",
"detail": "project was created within the last 90 days. Please review its contents carefully",
"points": 0,
"status": "missed",
"details": [],
"max_points": 7.5
},
{
"key": "packaging",
"name": "Packaging",
"detail": "packaging workflow not detected",
"points": 0,
"status": "excluded",
"details": [
{
"code": "no_data",
"params": {}
}
],
"max_points": 5
},
{
"key": "pinned_dependencies",
"name": "Pinned-Dependencies",
"detail": "dependency not pinned by hash detected -- score normalized to 0",
"points": 0,
"status": "missed",
"details": [],
"max_points": 5
},
{
"key": "sast",
"name": "SAST",
"detail": "SAST tool is not run on all commits -- score normalized to 0",
"points": 0,
"status": "missed",
"details": [],
"max_points": 5
},
{
"key": "security_policy",
"name": "Security-Policy",
"detail": "security policy file not detected",
"points": 0,
"status": "missed",
"details": [],
"max_points": 5
},
{
"key": "signed_releases",
"name": "Signed-Releases",
"detail": "Project has not signed or included provenance with any releases.",
"points": 0,
"status": "missed",
"details": [],
"max_points": 7.5
},
{
"key": "token_permissions",
"name": "Token-Permissions",
"detail": "detected GitHub workflow tokens with excessive permissions",
"points": 0,
"status": "missed",
"details": [],
"max_points": 7.5
},
{
"key": "vulnerabilities",
"name": "Vulnerabilities",
"detail": "1 existing vulnerabilities detected",
"points": 6.8,
"status": "partial",
"details": [],
"max_points": 7.5
}
]
},
{
"key": "dependency_advisories",
"band": "excellent",
"name": "Dependency advisories",
"note": "Matched the npm:@chrischall/gemini-mcp@1.0.3 runtime dependency closure — what installing the published package pulls in — 97 packages. Reachability is not analyzed.",
"notes": [
{
"code": "advisories_scope_published",
"params": {
"package": "npm:@chrischall/gemini-mcp@1.0.3",
"assessed": 97
}
},
{
"code": "advisories_reachability",
"params": {}
}
],
"value": 88,
"inputs": {
"source": "osv",
"advisories": 1,
"affected_packages": 1,
"assessed_packages": 97,
"unassessed_packages": 0,
"affected_by_severity": "moderate 1",
"direct_affected_packages": 0
},
"components": [
{
"key": "direct_dependencies_free_of_known_advisories",
"name": "Direct dependencies free of known advisories",
"detail": "no direct dependency carries a known advisory",
"points": 35,
"status": "met",
"details": [
{
"code": "no_direct_advisories",
"params": {}
}
],
"max_points": 35
},
{
"key": "indirect_dependencies_free_of_known_advisories",
"name": "Indirect dependencies free of known advisories",
"detail": "1 affected: @hono/node-server 1.19.15 (moderate 5.9)",
"points": 13.2,
"status": "partial",
"details": [
{
"code": "advisories_affected",
"params": {
"count": 1,
"packages": "@hono/node-server 1.19.15 (moderate 5.9)"
}
}
],
"max_points": 25
},
{
"key": "no_advisories_left_outstanding",
"name": "No advisories left outstanding",
"detail": "no advisory has been public longer than 90 days",
"points": 40,
"status": "met",
"details": [
{
"code": "advisories_none_stale",
"params": {
"days": 90
}
}
],
"max_points": 40
}
]
},
{
"key": "malicious_dependencies",
"band": "excellent",
"name": "Malicious dependencies",
"note": null,
"notes": [],
"value": 100,
"inputs": {
"source": "osv",
"meaning": "reported as a malicious package by the OpenSSF corpus; the remedy is removal or moving off the compromised name, never an upgrade of the same artifact. Versions the registry has since pulled are listed but not scored",
"packages": [],
"red_flag": false,
"assessed_packages": 97,
"malicious_packages": 0,
"direct_malicious_packages": 0,
"withdrawn_malicious_packages": 0,
"installable_malicious_packages": 0
},
"components": [
{
"key": "no_dependency_reported_as_a_malicious_package",
"name": "No dependency reported as a malicious package",
"detail": "no dependency is reported as a malicious package",
"points": 100,
"status": "met",
"details": [
{
"code": "no_malicious_dependencies",
"params": {}
}
],
"max_points": 100
}
]
}
],
"description": "Are visible security and supply-chain practices strong, with no malicious dependency and no unresolved high-risk jurisdiction exposure?"
},
{
"key": "ai_readiness",
"band": "moderate",
"name": "AI Readiness",
"value": 68,
"weight": 0,
"metrics": [
{
"key": "ai_agent_context",
"band": "excellent",
"name": "Agent context & guidance",
"note": null,
"notes": [],
"value": 85,
"inputs": {
"has_llms_txt": false,
"legible_history_share": 1,
"agent_instruction_files": [
"CLAUDE.md"
],
"agent_instruction_max_bytes": 33502
},
"components": [
{
"key": "agent_instructions",
"name": "Agent instructions",
"detail": "CLAUDE.md",
"points": 45,
"status": "met",
"details": [
{
"code": "file_list",
"params": {
"files": "CLAUDE.md"
}
}
],
"max_points": 45
},
{
"key": "machine_readable_docs_llms_txt",
"name": "Machine-readable docs (llms.txt)",
"detail": null,
"points": 0,
"status": "missed",
"details": [],
"max_points": 15
},
{
"key": "legible_commit_history",
"name": "Legible commit history",
"detail": "67 of 67 human commits state their intent (structured subject or explanatory body)",
"points": 40,
"status": "met",
"details": [
{
"code": "legible_history",
"params": {
"legible": 67,
"sampled": 67
}
}
],
"max_points": 40
}
]
},
{
"key": "ai_verify_loop",
"band": "moderate",
"name": "Verify loop (build / test / typecheck)",
"note": null,
"notes": [],
"value": 61,
"inputs": {
"has_nix": false,
"has_tests": true,
"lockfiles": [
"package-lock.json"
],
"has_dockerfile": false,
"typed_language": true,
"bootstrap_files": [],
"has_devcontainer": false,
"has_linter_config": false,
"typecheck_configs": [
"tsconfig.json"
],
"agent_commit_share": 0.558,
"toolchain_manifests": [],
"dependency_bot_commit_share": 0.221
},
"components": [
{
"key": "one_command_bootstrap",
"name": "One-command bootstrap",
"detail": null,
"points": 0,
"status": "missed",
"details": [],
"max_points": 18
},
{
"key": "automated_tests",
"name": "Automated tests",
"detail": null,
"points": 22,
"status": "met",
"details": [],
"max_points": 22
},
{
"key": "lint_format_config",
"name": "Lint / format config",
"detail": null,
"points": 0,
"status": "missed",
"details": [],
"max_points": 11
},
{
"key": "static_type_checking",
"name": "Static type checking",
"detail": "tsconfig.json",
"points": 11,
"status": "met",
"details": [
{
"code": "file_list",
"params": {
"files": "tsconfig.json"
}
}
],
"max_points": 11
},
{
"key": "reproducible_environment",
"name": "Reproducible environment",
"detail": "lockfile",
"points": 10,
"status": "met",
"details": [
{
"code": "file_list",
"params": {
"files": "lockfile"
}
}
],
"max_points": 10
},
{
"key": "demonstrated_agent_practice",
"name": "Demonstrated agent practice",
"detail": "48 of the last 86 commits agent-authored or agent-credited",
"points": 10,
"status": "met",
"details": [
{
"code": "agent_authored_commits",
"params": {
"count": 48,
"sampled": 86
}
}
],
"max_points": 10
},
{
"key": "automated_maintenance",
"name": "Automated maintenance",
"detail": "19 of the last 86 commits are automated dependency updates",
"points": 8,
"status": "met",
"details": [
{
"code": "dependency_bot_commits",
"params": {
"count": 19,
"sampled": 86
}
}
],
"max_points": 8
},
{
"key": "openssf_scorecard_pinned_dependencies",
"name": "OpenSSF Scorecard: Pinned-Dependencies",
"detail": "dependency not pinned by hash detected -- score normalized to 0",
"points": 0,
"status": "missed",
"details": [],
"max_points": 10
}
]
},
{
"key": "ai_code_legibility",
"band": "excellent",
"name": "Code legibility for models",
"note": null,
"notes": [],
"value": 100,
"inputs": {
"primary_language": "TypeScript",
"largest_source_bytes": 49918,
"source_files_sampled": 56,
"oversized_source_files": 0
},
"components": [
{
"key": "type_checkable_code",
"name": "Type-checkable code",
"detail": "TypeScript (statically typed)",
"points": 45,
"status": "met",
"details": [
{
"code": "statically_typed_language",
"params": {
"language": "TypeScript"
}
}
],
"max_points": 45
},
{
"key": "manageable_file_sizes",
"name": "Manageable file sizes",
"detail": "0/56 source files over 60KB",
"points": 55,
"status": "met",
"details": [
{
"code": "oversized_source_files",
"params": {
"kb": 60,
"sampled": 56,
"oversized": 0
}
}
],
"max_points": 55
}
]
},
{
"key": "ai_interfaces",
"band": "critical",
"name": "Machine-readable interfaces",
"note": null,
"notes": [],
"value": 20,
"inputs": {
"example_dirs": [],
"has_mcp_signal": true,
"api_schema_files": []
},
"components": [
{
"key": "api_schema_openapi_graphql_proto",
"name": "API schema (OpenAPI/GraphQL/proto)",
"detail": null,
"points": 0,
"status": "missed",
"details": [],
"max_points": 40
},
{
"key": "mcp_server",
"name": "MCP server",
"detail": null,
"points": 20,
"status": "met",
"details": [],
"max_points": 20
},
{
"key": "runnable_examples",
"name": "Runnable examples",
"detail": null,
"points": 0,
"status": "missed",
"details": [],
"max_points": 40
}
]
}
],
"description": "How well is the repo equipped to be developed and maintained with AI coding agents? An independent, experimental badge — weight 0.0, so it is surfaced on its own and does not affect the overall health score."
}
],
"metrics_version": "1.13.0"
},
"warnings": [],
"report_type": "repository",
"generated_at": "2026-07-25T15:23:32.587822Z",
"schema_version": "0.27.0",
"badge_url": "https://raw.githubusercontent.com/inspect-software/badges/main/v1/c/chrischall/gemini-mcp.svg",
"full_name": "chrischall/gemini-mcp",
"license_state": "standard",
"license_spdx": "MIT"
}